{"id":"CVE-2019-20394","details":"A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.","modified":"2026-08-07T15:18:51.801316Z","published":"2020-01-22T22:15:10.330Z","references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00019.html"},{"type":"ADVISORY","url":"https://github.com/CESNET/libyang/compare/v1.0-r2...v1.0-r3"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1793932"},{"type":"FIX","url":"https://github.com/CESNET/libyang/commit/6cc51b1757dfbb7cff92de074ada65e8523289a6"},{"type":"EVIDENCE","url":"https://github.com/CESNET/libyang/issues/769"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cesnet/libyang","events":[{"introduced":"14a95280b2bd77b5fd1d9b5f8af71b15679f1a8f"},{"last_affected":"347246611b85e05d16f54faaa5697c4b2ee4b468"},{"fixed":"6cc51b1757dfbb7cff92de074ada65e8523289a6"}],"database_specific":{"cpe":["cpe:2.3:a:cesnet:libyang:0.11:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.11:r2:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.12:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.12:r2:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.13:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.13:r2:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.14:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.15:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.16:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.16:r2:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:0.16:r3:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:1.0:r1:*:*:*:*:*:*","cpe:2.3:a:cesnet:libyang:1.0:r2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.11-r1"},{"last_affected":"0.11-r1"},{"introduced":"0.11-r2"},{"last_affected":"0.11-r2"},{"introduced":"0.12-r1"},{"last_affected":"0.12-r1"},{"introduced":"0.12-r2"},{"last_affected":"0.12-r2"},{"introduced":"0.13-r1"},{"last_affected":"0.13-r1"},{"introduced":"0.13-r2"},{"last_affected":"0.13-r2"},{"introduced":"0.14-r1"},{"last_affected":"0.14-r1"},{"introduced":"0.15-r1"},{"last_affected":"0.15-r1"},{"introduced":"0.16-r1"},{"last_affected":"0.16-r1"},{"introduced":"0.16-r2"},{"last_affected":"0.16-r2"},{"introduced":"0.16-r3"},{"last_affected":"0.16-r3"},{"introduced":"1.0-r1"},{"last_affected":"1.0-r1"},{"introduced":"1.0-r2"},{"last_affected":"1.0-r2"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.11-r1","0.11-r2","0.12-r1","0.12-r2","0.13-r1","0.13-r2","0.14-r1","0.15-r1","0.16-r1","0.16-r2","0.16-r3","1.0-r1","1.0-r2","v1.0-r2","v1.0-r1","v0.16-r2","v0.16-r1","v0.15-r1","v0.14-r1","v0.13-r2","v0.12-r2","v0.12-r1","v0.11-r2","v0.11-r1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20394.json","vanir_signatures_modified":"2026-08-07T15:18:51Z","vanir_signatures":[{"source":"https://github.com/cesnet/libyang/commit/6cc51b1757dfbb7cff92de074ada65e8523289a6","target":{"file":"src/parser_yang_bis.c","function":"yyparse"},"deprecated":false,"digest":{"function_hash":"334333495555913111835902825800076662424","length":121759},"id":"CVE-2019-20394-41732613","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["164382308562417233091935855972747064438","44550129803751250994624942069642899974","132892422234432367498765861481733659786","71028133021889715123863036278562934561"],"threshold":0.9},"id":"CVE-2019-20394-c15508ec","signature_type":"Line","signature_version":"v1","source":"https://github.com/cesnet/libyang/commit/6cc51b1757dfbb7cff92de074ada65e8523289a6","target":{"file":"src/parser_yang_bis.c"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}