Logo
vulnerabilityCVE-2022-3171
Name
CVE-2022-3171
Source
NVD ( link)Debian ( link)
Description
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
protobuf
Exploitable

Vulnerability Ratings#


4.3
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
29.3
Not Affected
buildroot
master
35.1
Not Affected
openwrt
master
29.5-r1
Not Affected
openwrt
master
3.17.3-r1
Exploitable
openwrt
master
5.29.5-r1
Not Affected
yocto
kirkstone
3.19.6
Not Affected
yocto
master
6.33.6
Not Affected
yocto
scarthgap
4.25.8
Not Affected