CVE-2021-22569
published 2022-01-10CVE-2021-22569: An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small…
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| google-protobuf | < 3.19.2 | 3.19.2 | |
| google-protobuf | >= 0 < 3.19.2 | 3.19.2 | |
| protobuf | >= 0 < 3.12.4-1+deb11u1 | 3.12.4-1+deb11u1 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.0.0-9.1ubuntu1.1 | 3.0.0-9.1ubuntu1.1 | |
| protobuf | >= 0 < 3.6.1.3-2ubuntu5.2 | 3.6.1.3-2ubuntu5.2 | |
| protobuf | >= 0 < 3.12.4-1ubuntu7.22.04.1 | 3.12.4-1ubuntu7.22.04.1 | |
| protobuf | >= 0 < 2.5.0-9ubuntu1+esm1 | 2.5.0-9ubuntu1+esm1 | |
| protobuf-java | < 3.16.1 | 3.16.1 | |
| protobuf-java | >= 3.18.0 < 3.18.2 | 3.18.2 | |
| protobuf-java | >= 3.19.0 < 3.19.2 | 3.19.2 | |
| protobuf-kotlin | < 3.18.2 | 3.18.2 | |
| protobuf-kotlin | >= 3.19.0 < 3.19.2 | 3.19.2 | |
| google_llc | google-protobuf | >= unspecified < 3.19.2 | 3.19.2 |
| google_llc | protobuf-java | >= unspecified < 3.16.1 | 3.16.1 |
| google_llc | protobuf-java | >= unspecified < 3.18.2 | 3.18.2 |
| google_llc | protobuf-java | >= unspecified < 3.19.2 | 3.19.2 |
| google_llc | protobuf-kotlin | >= unspecified < 3.18.2 | 3.18.2 |
| google_llc | protobuf-kotlin | >= unspecified < 3.19.2 | 3.19.2 |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-5_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ghsa5.5MEDIUM
osv5.5MEDIUM