CVE-2021-22569
10.01.2022, 14:10
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.Enginsight
Vendor | Product | Version |
---|---|---|
google-protobuf | 𝑥 < 3.19.2 | |
protobuf-java | 𝑥 < 3.16.1 | |
protobuf-java | 3.18.0 ≤ 𝑥 < 3.18.2 | |
protobuf-java | 3.19.0 ≤ 𝑥 < 3.19.2 | |
protobuf-kotlin | 𝑥 < 3.18.2 | |
protobuf-kotlin | 3.19.0 ≤ 𝑥 < 3.19.2 | |
oracle | communications_cloud_native_core_console | 1.9.0 |
oracle | communications_cloud_native_core_network_repository_function | 1.15.0 |
oracle | communications_cloud_native_core_network_repository_function | 1.15.1 |
oracle | communications_cloud_native_core_policy | 1.15.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References