CVE-2023-26916: Cesnet Libyang

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.

Affected products

  • Cesnet Libyang: from 2.0.164, up to and including 2.1.30
  • Fedoraproject Fedora: version 36 only; version 37 only

Published 2023-04-03. Last modified 2026-06-17.