SUSE-SU-2022:3245-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3245-1
SUSE-SU-2022:3245-1
Summary: Security update for libyang
Details: This update for libyang fixes the following issues: - CVE-2021-28906: Fixed missing check in read_yin_leaf that can lead to DoS (bsc#1186378) - CVE-2021-28904: Fixed missing check in ext_get_plugin that lead to DoS (bsc#1186376). - CVE-2021-28903: Fixed stack overflow in lyxml_parse_mem (bsc#1186375). - CVE-2021-28902: Fixed missing check in read_yin_container that can lead to DoS (bsc#1186374).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223245-1/, https://bugzilla.suse.com/1186374, https://bugzilla.suse.com/1186375, https://bugzilla.suse.com/1186376, https://bugzilla.suse.com/1186378, https://www.suse.com/security/cve/CVE-2021-28902, https://www.suse.com/security/cve/CVE-2021-28903, https://www.suse.com/security/cve/CVE-2021-28904, https://www.suse.com/security/cve/CVE-2021-28906
Affected packages
Package
Name: libyang
Purl: pkg:rpm/suse/libyang&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
