UBUNTU-CVE-2021-22569
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-22569
UBUNTU-CVE-2021-22569
Summary:
Details: An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
References: https://ubuntu.com/security/CVE-2021-22569, https://www.openwall.com/lists/oss-security/2022/01/12/4, https://cloud.google.com/support/bulletins#gcp-2022-001, http://www.openwall.com/lists/oss-security/2022/01/12/4, http://www.openwall.com/lists/oss-security/2022/01/12/7, https://ubuntu.com/security/notices/USN-5945-1, https://www.cve.org/CVERecord?id=CVE-2021-22569
Affected packages
Package
Name: protobuf
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
