CVE-2022-1941
published 2022-09-22CVE-2022-1941: A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.18%
64.2th percentile
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | protobuf | < protobuf 3.21.9-3 (bookworm) | protobuf 3.21.9-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| protobuf | >= 0 < 3.12.4-1+deb11u1 | 3.12.4-1+deb11u1 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.21.9-3 | 3.21.9-3 | |
| protobuf | >= 0 < 3.18.3 | 3.18.3 | |
| protobuf | >= 0 < 3.0.0-9.1ubuntu1.1 | 3.0.0-9.1ubuntu1.1 | |
| protobuf | >= 0 < 3.6.1.3-2ubuntu5.2 | 3.6.1.3-2ubuntu5.2 | |
| protobuf | >= 0 < 3.12.4-1ubuntu7.22.04.1 | 3.12.4-1ubuntu7.22.04.1 | |
| protobuf | >= 0 < 2.5.0-9ubuntu1+esm1 | 2.5.0-9ubuntu1+esm1 | |
| protobuf | >= 0 < 2.6.1-1.3ubuntu0.1~esm2 | 2.6.1-1.3ubuntu0.1~esm2 | |
| protobuf | >= 3.19.0 < 3.19.5 | 3.19.5 | |
| protobuf | >= 3.20.0 < 3.20.2 | 3.20.2 | |
| protobuf | >= 4.0.0 < 4.21.6 | 4.21.6 | |
| protobuf-cpp | < 3.18.3 | 3.18.3 | |
| protobuf-cpp | >= 3.19.0 < 3.19.5 | 3.19.5 | |
| protobuf-cpp | >= 3.20.0 < 3.20.2 | 3.20.2 | |
| protobuf-cpp | >= 3.21.0 < 3.21.6 | 3.21.6 | |
| protobuf-python | < 3.18.3 | 3.18.3 | |
| protobuf-python | >= 3.19.0 < 3.19.5 | 3.19.5 | |
| protobuf-python | >= 3.20.0 < 3.20.2 | 3.20.2 | |
| protobuf-python | >= 4.0.0 < 4.21.6 | 4.21.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Protocol Buffers vulnerabilities
vendor_ubuntu·2023-03-13·CVSS 7.5
CVE-2021-22570 [HIGH] Protocol Buffers vulnerabilities
Title: Protocol Buffers vulnerabilities
Summary: Several security issues were fixed in Protocol Buffers.
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to cras
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/Python (Python) — CVE-2022-1941
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-1941 [HIGH] Oracle Oracle MySQL Risk Matrix: Connector/Python (Python) — CVE-2022-1941
Oracle Oracle MySQL Risk Matrix: Connector/Python (Python) vulnerability
CVE: CVE-2022-1941
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
protobuf vulnerabilities
vendor_ubuntu·2022-12-08·CVSS 8.8
CVE-2022-1941 [HIGH] protobuf vulnerabilities
Title: protobuf vulnerabilities
Summary: Several security issues were fixed in protobuf.
It was discovered that protobuf did not properly manage memory when serializing
large messages. An attacker could possibly use this issue to cause applications
using protobuf to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2015-5237)
It was discovered that protobuf did not properly manage memory when parsing
specifically crafted messages. An attacker could possibly use this issue to
cause applications using protobuf to crash, resulting in a denial of service.
(CVE-2022-1941)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
protobuf: message parsing vulnerability in ProtocolBuffers
vendor_redhat·2022-09-22·CVSS 7.5
CVE-2022-1941 [HIGH] CWE-1286 protobuf: message parsing vulnerability in ProtocolBuffers
protobuf: message parsing vulnerability in ProtocolBuffers
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
A parsing vulnerability for the MessageSet type in the ProtocolBuf
Microsoft
Out of Memory issue in ProtocolBuffers for cpp and python
vendor_msrc·2022-09-13·CVSS 7.5
CVE-2022-1941 [HIGH] CWE-1286 Out of Memory issue in ProtocolBuffers for cpp and python
Out of Memory issue in ProtocolBuffers for cpp and python
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Debian
CVE-2022-1941: protobuf - A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions ...
vendor_debian·2022·CVSS 7.5
CVE-2022-1941 [HIGH] CVE-2022-1941: protobuf - A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions ...
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
Scope: local
bookworm: resolved (fixed in 3.21.9-3)
bullseye: resolved (fixed in 3.12.4-1+deb11u1)
forky: resolved (fixed in 3.
OSV
protobuf vulnerabilities
osv·2023-03-13·CVSS 5.5
CVE-2021-22569 [MEDIUM] protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)
It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)
It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to crash, resulting in a denial
of service. This issue only affected Ubuntu 18.04 LTS, U
OSV
protobuf vulnerabilities
osv·2022-12-08·CVSS 8.8
CVE-2015-5237 [HIGH] protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that protobuf did not properly manage memory when serializing
large messages. An attacker could possibly use this issue to cause applications
using protobuf to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2015-5237)
It was discovered that protobuf did not properly manage memory when parsing
specifically crafted messages. An attacker could possibly use this issue to
cause applications using protobuf to crash, resulting in a denial of service.
(CVE-2022-1941)
GHSA
protobuf-cpp and protobuf-python have potential Denial of Service issue
ghsa·2022-09-23
CVE-2022-1941 [HIGH] CWE-119 protobuf-cpp and protobuf-python have potential Denial of Service issue
protobuf-cpp and protobuf-python have potential Denial of Service issue
### Summary
A message parsing and memory management vulnerability in ProtocolBuffer’s C++ and Python implementations can trigger an out of memory (OOM) failure when processing a specially crafted message, which could lead to a denial of service (DoS) on services using the libraries.
Reporter: [ClusterFuzz](https://google.github.io/clusterfuzz/)
Affected versions: All versions of C++ Protobufs (including Python) prior to the versions listed below.
### Severity & Impact
As scored by google
**Medium 5.7** - [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Asscored byt NIST
**High 7.5** - [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
OSV
protobuf-cpp and protobuf-python have potential Denial of Service issue
osv·2022-09-23
CVE-2022-1941 [HIGH] protobuf-cpp and protobuf-python have potential Denial of Service issue
protobuf-cpp and protobuf-python have potential Denial of Service issue
### Summary
A message parsing and memory management vulnerability in ProtocolBuffer’s C++ and Python implementations can trigger an out of memory (OOM) failure when processing a specially crafted message, which could lead to a denial of service (DoS) on services using the libraries.
Reporter: [ClusterFuzz](https://google.github.io/clusterfuzz/)
Affected versions: All versions of C++ Protobufs (including Python) prior to the versions listed below.
### Severity & Impact
As scored by google
**Medium 5.7** - [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Asscored byt NIST
**High 7.5** - [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
OSV
CVE-2022-1941: A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3
osv·2022-09-22·CVSS 7.5
CVE-2022-1941 [HIGH] CVE-2022-1941: A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/09/27/1https://cloud.google.com/support/bulletins#GCP-2022-019https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hfhttps://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/https://security.netapp.com/advisory/ntap-20240705-0001/http://www.openwall.com/lists/oss-security/2022/09/27/1https://cloud.google.com/support/bulletins#GCP-2022-019https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hfhttps://lists.debian.org/debian-lts-announce/2023/04/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/https://security.netapp.com/advisory/ntap-20240705-0001/
2022-09-22
Published