CVE-2021-22570
Published: 26 January 2022
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Priority
Status
Package | Release | Status |
---|---|---|
protobuf Launchpad, Ubuntu, Debian |
jammy |
Released
(3.12.4-1ubuntu7.22.04.1)
|
kinetic |
Released
(3.12.4-1ubuntu7.22.10.1)
|
|
lunar |
Not vulnerable
(3.21.12-1ubuntu6)
|
|
bionic |
Released
(3.0.0-9.1ubuntu1.1)
|
|
focal |
Released
(3.6.1.3-2ubuntu5.2)
|
|
impish |
Ignored
(end of life)
|
|
trusty |
Released
(2.5.0-9ubuntu1+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
upstream |
Released
(3.15.0)
|
|
xenial |
Released
(2.6.1-1.3ubuntu0.1~esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |