A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxmlparsemem(). lyxmlparseelem() function will be called recursively, which will consume stack space and lead to crash.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "3.7.8-3", "binary_name": "libyang-dev" }, { "binary_version": "3.7.8-3", "binary_name": "libyang3" }, { "binary_version": "3.7.8-3", "binary_name": "libyang3-dbgsym" }, { "binary_version": "3.7.8-3", "binary_name": "libyang3-tools" }, { "binary_version": "3.7.8-3", "binary_name": "libyang3-tools-dbgsym" } ] }