CVE-2021-22569 PUBLISHED

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

EPSS 0.27% · 50.1th percentile

Risk Scores

EPSS Score
0.27%
50.1th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSprotobuf3.12.4-1ubuntu3, 0, 3.12.4-1ubuntu7
Ubuntu:20.04:LTSprotobuf3.6.1.3-2ubuntu1, 3.6.1.3-2, 0
Ubuntu:Pro:14.04:LTSprotobuf0, 2.4.1-3ubuntu2, 2.4.1-3ubuntu3
Ubuntu:Pro:16.04:LTSprotobuf0, 2.6.1-1.3ubuntu0.1~esm4, 2.6.1-1.3ubuntu0.1~esm1
Ubuntu:18.04:LTSprotobuf3.0.0-9.1ubuntu1, 3.0.0-9ubuntu6, 3.0.0-9ubuntu5

Timeline

References

Open in Interactive Console →