CVE-2021-22570
published 2022-01-26CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
2.66%
84.0th percentile
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | protocolbuffers_protobuf | >= 0 < 0.0.0-20210218195015-ae50d9b99025 | 0.0.0-20210218195015-ae50d9b99025 |
| github.com | protocolbuffers_protobuf | >= 0.0.0 < 3.15.0 | 3.15.0 |
| protobuf | < 3.15.0 | 3.15.0 | |
| protobuf | >= 0 < 3.12.4-1+deb11u1 | 3.12.4-1+deb11u1 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.15.0 | 3.15.0 | |
| protobuf | >= 0 < 3.15.0 | 3.15.0 | |
| protobuf | >= 0 < 3.0.0-9.1ubuntu1.1 | 3.0.0-9.1ubuntu1.1 | |
| protobuf | >= 0 < 3.6.1.3-2ubuntu5.2 | 3.6.1.3-2ubuntu5.2 | |
| protobuf | >= 0 < 3.12.4-1ubuntu7.22.04.1 | 3.12.4-1ubuntu7.22.04.1 | |
| protobuf | >= 0 < 2.5.0-9ubuntu1+esm1 | 2.5.0-9ubuntu1+esm1 | |
| google_llc | protobuf | >= unspecified < 3.15.0 | 3.15.0 |
| msrc | cbl2_mysql_8.0.29-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_protobuf_3.14.0-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_oracle7.5MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Protocol Buffers vulnerabilities
vendor_ubuntu·2023-03-13·CVSS 7.5
CVE-2021-22570 [HIGH] Protocol Buffers vulnerabilities
Title: Protocol Buffers vulnerabilities
Summary: Several security issues were fixed in Protocol Buffers.
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to cras
Ubuntu
Protocol Buffers vulnerability
vendor_ubuntu·2022-06-21
CVE-2021-22570 Protocol Buffers vulnerability
Title: Protocol Buffers vulnerability
Summary: Protocol Buffers could be made to crash if it received specially crafted
input.
It was discovered that Protocol Buffers did not properly parse certain symbols.
An attacker could possibly use this issue to cause a denial of service or other
unspecified impact.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) — CVE-2021-22570
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-22570 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) — CVE-2021-22570
Oracle Oracle MySQL Risk Matrix: Server: Compiling (protobuf) vulnerability
CVE: CVE-2021-22570
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference
vendor_redhat·2022-01-26·CVSS 6.5
CVE-2021-22570 [MEDIUM] CWE-476 protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference
protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
A flaw was found in protobuf. The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference. This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory.
Package: protobuf (Red Hat Enterprise Linux 7) - Out of support scope
Package: openshift4/ose-kuryr-cni-rhel8 (Red Hat OpenShi
Microsoft
Nullptr Dereference in Protobuf
vendor_msrc·2022-01-11·CVSS 5.5
CVE-2021-22570 [MEDIUM] CWE-476 Nullptr Dereference in Protobuf
Nullptr Dereference in Protobuf
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/a
Debian
CVE-2021-22570: protobuf - Nullptr dereference when a null char is present in a proto symbol. The symbol is...
vendor_debian·2021·CVSS 6.5
CVE-2021-22570 [MEDIUM] CVE-2021-22570: protobuf - Nullptr dereference when a null char is present in a proto symbol. The symbol is...
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: resolved (fixed in 3.12.4-1+deb11u1)
forky: resolved (fixed in 3.21.9-3)
sid: resolved (fixed in 3.21.9-3)
trixie: resolved (fixed in 3.21.9-3)
OSV
protobuf vulnerabilities
osv·2023-03-13·CVSS 5.5
CVE-2021-22569 [MEDIUM] protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to crash, resulting in a denial
of service. This issue only affected Ubuntu 18.04 LTS, U
OSV
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
osv·2022-01-27
CVE-2021-22570 [HIGH] Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
### Withdrawn Advisory
This advisory has been withdrawn because the protobuf vulnerability comes from the compiler rather that the code. This link is maintained to preserve external references.
### Original Description
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
GHSA
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
ghsa·2022-01-27
CVE-2021-22570 [HIGH] CWE-476 Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
### Withdrawn Advisory
This advisory has been withdrawn because the protobuf vulnerability comes from the compiler rather that the code. This link is maintained to preserve external references.
### Original Description
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
OSV
CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol
osv·2022-01-26·CVSS 5.5
CVE-2021-22570 [MEDIUM] CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0https://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/https://security.netapp.com/advisory/ntap-20220429-0005/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0https://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/https://security.netapp.com/advisory/ntap-20220429-0005/https://www.oracle.com/security-alerts/cpuapr2022.html
2022-01-26
Published