Logo
vulnerabilityCVE-2021-22569
Name
CVE-2021-22569
Source
NVD ( link)Debian ( link)
Description
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
protobuf-compat
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
5.5
CVSSv31
4.3
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
29.3
Not Affected
buildroot
master
35.1
Not Affected
openwrt
openwrt-25.12
3.17.3-r3
Exploitable
yocto
kirkstone
3.19.6
Not Affected
yocto
master
6.33.6
Not Affected
yocto
scarthgap
4.25.8
Not Affected