CVE-2021-22569
published 2022-01-10CVE-2021-22569: An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.65%
73.8th percentile
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| google-protobuf | < 3.19.2 | 3.19.2 | |
| google-protobuf | >= 0 < 3.19.2 | 3.19.2 | |
| protobuf | >= 0 < 3.12.4-1+deb11u1 | 3.12.4-1+deb11u1 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.0.0-9.1ubuntu1.1 | 3.0.0-9.1ubuntu1.1 | |
| protobuf | >= 0 < 3.6.1.3-2ubuntu5.2 | 3.6.1.3-2ubuntu5.2 | |
| protobuf | >= 0 < 3.12.4-1ubuntu7.22.04.1 | 3.12.4-1ubuntu7.22.04.1 | |
| protobuf | >= 0 < 2.5.0-9ubuntu1+esm1 | 2.5.0-9ubuntu1+esm1 | |
| protobuf-java | < 3.16.1 | 3.16.1 | |
| protobuf-java | >= 3.18.0 < 3.18.2 | 3.18.2 | |
| protobuf-java | >= 3.19.0 < 3.19.2 | 3.19.2 | |
| protobuf-kotlin | < 3.18.2 | 3.18.2 | |
| protobuf-kotlin | >= 3.19.0 < 3.19.2 | 3.19.2 | |
| google_llc | google-protobuf | >= unspecified < 3.19.2 | 3.19.2 |
| google_llc | protobuf-java | >= unspecified < 3.16.1 | 3.16.1 |
| google_llc | protobuf-java | >= unspecified < 3.18.2 | 3.18.2 |
| google_llc | protobuf-java | >= unspecified < 3.19.2 | 3.19.2 |
| google_llc | protobuf-kotlin | >= unspecified < 3.18.2 | 3.18.2 |
| google_llc | protobuf-kotlin | >= unspecified < 3.19.2 | 3.19.2 |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-5_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
vendor_msrc5.5MEDIUM
vendor_oracle5.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
protobuf vulnerabilities
osv·2023-03-13·CVSS 5.5
CVE-2021-22569 [MEDIUM] protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to crash, resulting in a denial
of service. This issue only affected Ubuntu 18.04 LTS, U
OSV
skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
osv·2022-07-21·CVSS 5.5
CVE-2021-22569 [MEDIUM] skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
### Impact
Vulnerable library protobuf-java 3.11.4 (CVE-2021-22569)
### Patches
Dependency updated in jadx 1.4.3
### References
According to the AquaSecurity report:
Also, Maven repository have links to this and other vulnerabilities from dependencies:
https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java/3.11.4
GHSA
skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
ghsa·2022-07-21·CVSS 5.5
CVE-2021-22569 [MEDIUM] CWE-696 skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
skylot jadx affected by Incorrect Behavior Order in vulnerable dependency
### Impact
Vulnerable library protobuf-java 3.11.4 (CVE-2021-22569)
### Patches
Dependency updated in jadx 1.4.3
### References
According to the AquaSecurity report:
Also, Maven repository have links to this and other vulnerabilities from dependencies:
https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java/3.11.4
OSV
CVE-2021-22569: An issue in protobuf-java allowed the interleaving of com
osv·2022-01-10·CVSS 5.5
CVE-2021-22569 [MEDIUM] CVE-2021-22569: An issue in protobuf-java allowed the interleaving of com
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
OSV
A potential Denial of Service issue in protobuf-java
osv·2022-01-07·CVSS 5.5
CVE-2021-22569 [MEDIUM] A potential Denial of Service issue in protobuf-java
A potential Denial of Service issue in protobuf-java
## Summary
A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.
Reporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)
Affected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf "javalite" users (typically Android) are not affected.
## Severity
[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5, An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.
## Proof of Concept
For r
GHSA
A potential Denial of Service issue in protobuf-java
ghsa·2022-01-07·CVSS 5.5
CVE-2021-22569 [MEDIUM] CWE-696 A potential Denial of Service issue in protobuf-java
A potential Denial of Service issue in protobuf-java
## Summary
A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.
Reporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)
Affected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf "javalite" users (typically Android) are not affected.
## Severity
[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5, An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.
## Proof of Concept
For r
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) — CVE-2021-22569
vendor_oracle·2023-07-15·CVSS 5.5
CVE-2021-22569 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) — CVE-2021-22569
Oracle Oracle Communications Applications Risk Matrix: Security (Google Protobuf-Java) vulnerability
CVE: CVE-2021-22569
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Google Protobuf-Java) — CVE-2021-22569
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2021-22569 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Google Protobuf-Java) — CVE-2021-22569
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Google Protobuf-Java) vulnerability
CVE: CVE-2021-22569
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Protocol Buffers vulnerabilities
vendor_ubuntu·2023-03-13·CVSS 7.5
CVE-2021-22570 [HIGH] Protocol Buffers vulnerabilities
Title: Protocol Buffers vulnerabilities
Summary: Several security issues were fixed in Protocol Buffers.
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to cras
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph MapViewer (protobuf-java) — CVE-2021-22569
vendor_oracle·2022-04-15·CVSS 2.8
CVE-2021-22569 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph MapViewer (protobuf-java) — CVE-2021-22569
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph MapViewer (protobuf-java) vulnerability
CVE: CVE-2021-22569
CVSS: 2.8
Protocol: Local Logon
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Microsoft
Denial of Service of protobuf-java parsing procedure
vendor_msrc·2022-01-11·CVSS 5.5
CVE-2021-22569 [HIGH] CWE-696 Denial of Service of protobuf-java parsing procedure
Denial of Service of protobuf-java parsing procedure
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.
Red Hat
protobuf-java: potential DoS in the parsing procedure for binary data
vendor_redhat·2022-01-06·CVSS 7.5
CVE-2021-22569 [HIGH] CWE-696 protobuf-java: potential DoS in the parsing procedure for binary data
protobuf-java: potential DoS in the parsing procedure for binary data
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
A flaw was found in protobuf-java. Google Protocol Buffer (protobuf-java) allows the interleaving of com.google.protobuf.UnknownFieldSet fields. By persuading a victim to open specially-crafted content, a remote attacker could cause a timeout in the ProtobufFuzzer function, resulting in a denial of service.
Package: openshift-logging/elasticsearch6-rhel8 (
Debian
CVE-2021-22569: protobuf - An issue in protobuf-java allowed the interleaving of com.google.protobuf.Unknow...
vendor_debian·2021·CVSS 7.5
CVE-2021-22569 [HIGH] CVE-2021-22569: protobuf - An issue in protobuf-java allowed the interleaving of com.google.protobuf.Unknow...
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: resolved (fixed in 3.12.4-1+deb11u1)
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/01/12/4http://www.openwall.com/lists/oss-security/2022/01/12/7https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39330https://cloud.google.com/support/bulletins#gcp-2022-001https://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2022/01/12/4http://www.openwall.com/lists/oss-security/2022/01/12/7https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39330https://cloud.google.com/support/bulletins#gcp-2022-001https://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.html
2022-01-10
Published