Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3393-1 | protobuf security update |
EUVD |
EUVD-2022-0206 | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater. |
Github GHSA |
GHSA-77rm-9x9h-xj3g | Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers |
Ubuntu USN |
USN-5490-1 | Protocol Buffers vulnerability |
Ubuntu USN |
USN-5945-1 | Protocol Buffers vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-04-21T13:56:58.459Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22570
Updated: 2024-08-03T18:44:13.764Z
Status : Modified
Published: 2022-01-26T14:15:08.067
Modified: 2024-11-21T05:50:20.810
Link: CVE-2021-22570
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN