In function read_yin_container() in libyang <= v1.0.225, it doesnt check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Libyang | Cesnet | * | 1.0.225 (including) | 
| Libyang | Ubuntu | esm-apps/focal | * | 
| Libyang | Ubuntu | esm-apps/jammy | * | 
| Libyang | Ubuntu | focal | * | 
| Libyang | Ubuntu | groovy | * | 
| Libyang | Ubuntu | hirsute | * | 
| Libyang | Ubuntu | impish | * | 
| Libyang | Ubuntu | jammy | * | 
| Libyang | Ubuntu | kinetic | * | 
| Libyang | Ubuntu | trusty | * | 
| Libyang | Ubuntu | upstream | * | 
| Libyang | Ubuntu | xenial | * |