{"api_version":"1","generated_at":"2026-04-23T02:37:07+00:00","cve":"CVE-2021-22570","urls":{"html":"https://cve.report/CVE-2021-22570","api":"https://cve.report/api/cve/CVE-2021-22570.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-22570","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-22570"},"summary":{"title":"CVE-2021-22570","description":"Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.","state":"PUBLIC","assigner":"security@google.com","published_at":"2022-01-26 14:15:00","updated_at":"2023-11-07 03:30:00"},"problem_types":["CWE-476"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/","name":"FEDORA-2022-d1a15f9cdb","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: chromium-99.0.4844.51-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/","name":"FEDORA-2022-fedff53e4e","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: mingw-protobuf-3.14.0-4.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/","name":"FEDORA-2022-d1a15f9cdb","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: chromium-99.0.4844.51-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/","name":"FEDORA-2022-ffe4a1cedd","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: protobuf-3.14.0-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","name":"https://www.oracle.com/security-alerts/cpuapr2022.html","refsource":"MISC","tags":[],"title":"Oracle Critical Patch Update Advisory - April 2022","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/","name":"FEDORA-2022-ffe4a1cedd","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: protobuf-3.14.0-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/","name":"FEDORA-2022-fedff53e4e","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: mingw-protobuf-3.14.0-4.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/","name":"FEDORA-2022-49b52819a4","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: chromium-99.0.4844.51-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html","name":"[debian-lts-announce] 20230418 [SECURITY] [DLA 3393-1] protobuf security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3393-1] protobuf security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/","name":"FEDORA-2022-2d3e6eb9e4","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: protobuf-3.14.0-7.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/","name":"FEDORA-2022-57923346cf","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: chromium-99.0.4844.51-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/","name":"FEDORA-2022-2d3e6eb9e4","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: protobuf-3.14.0-7.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/","name":"FEDORA-2022-486d5f349d","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: mingw-protobuf-3.14.0-4.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/","name":"FEDORA-2022-57923346cf","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: chromium-99.0.4844.51-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Release Protocol Buffers v3.15.0 · protocolbuffers/protobuf · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/","name":"FEDORA-2022-486d5f349d","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: mingw-protobuf-3.14.0-4.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20220429-0005/","name":"https://security.netapp.com/advisory/ntap-20220429-0005/","refsource":"CONFIRM","tags":[],"title":"April 2022 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/","name":"FEDORA-2022-49b52819a4","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: chromium-99.0.4844.51-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-22570","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22570","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"protobuf","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"active_iq_unified_manager","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"vmware_vsphere","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"active_iq_unified_manager","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"oncommand_insight","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"oncommand_workflow_automation","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"snapcenter","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22570","vulnerable":"1","versionEndIncluding":"8.0.28","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"mysql","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-22570","qid":"160224","title":"Oracle Enterprise Linux Security Update for protobuf (ELSA-2022-7464)"},{"cve":"CVE-2021-22570","qid":"160267","title":"Oracle Enterprise Linux Security Update for protobuf (ELSA-2022-7970)"},{"cve":"CVE-2021-22570","qid":"181741","title":"Debian Security Update for protobuf (DLA 3393-1)"},{"cve":"CVE-2021-22570","qid":"184001","title":"Debian Security Update for protobuf (CVE-2021-22570)"},{"cve":"CVE-2021-22570","qid":"199233","title":"Ubuntu Security Notification for Protocol Buffers Vulnerabilities (USN-5945-1)"},{"cve":"CVE-2021-22570","qid":"20256","title":"Oracle MySQL April 2022 Critical Patch Update (CPUAPR2022)"},{"cve":"CVE-2021-22570","qid":"240813","title":"Red Hat Update for protobuf (RHSA-2022:7464)"},{"cve":"CVE-2021-22570","qid":"240886","title":"Red Hat Update for protobuf (RHSA-2022:7970)"},{"cve":"CVE-2021-22570","qid":"240975","title":"Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8860)"},{"cve":"CVE-2021-22570","qid":"240986","title":"Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8847)"},{"cve":"CVE-2021-22570","qid":"282391","title":"Fedora Security Update for protobuf (FEDORA-2022-ffe4a1cedd)"},{"cve":"CVE-2021-22570","qid":"282446","title":"Fedora Security Update for protobuf (FEDORA-2022-2d3e6eb9e4)"},{"cve":"CVE-2021-22570","qid":"282464","title":"Fedora Security Update for mingw (FEDORA-2022-486d5f349d)"},{"cve":"CVE-2021-22570","qid":"282465","title":"Fedora Security Update for mingw (FEDORA-2022-fedff53e4e)"},{"cve":"CVE-2021-22570","qid":"282470","title":"Fedora Security Update for chromium (FEDORA-2022-d1a15f9cdb)"},{"cve":"CVE-2021-22570","qid":"282480","title":"Fedora Security Update for chromium (FEDORA-2022-49b52819a4)"},{"cve":"CVE-2021-22570","qid":"354330","title":"Amazon Linux Security Advisory for protobuf : ALAS2022-2022-098"},{"cve":"CVE-2021-22570","qid":"354462","title":"Amazon Linux Security Advisory for protobuf : ALAS2022-2022-165"},{"cve":"CVE-2021-22570","qid":"354721","title":"Amazon Linux Security Advisory for protobuf : ALAS-2023-1676"},{"cve":"CVE-2021-22570","qid":"354729","title":"Amazon Linux Security Advisory for protobuf : ALAS2-2023-1931"},{"cve":"CVE-2021-22570","qid":"354772","title":"Amazon Linux Security Advisory for protobuf : ALAS2-2023-1948"},{"cve":"CVE-2021-22570","qid":"355275","title":"Amazon Linux Security Advisory for protobuf : ALAS2023-2023-009"},{"cve":"CVE-2021-22570","qid":"379050","title":"Splunk Enterprise Multiple Vulnerabilities (SVD-2023-1104,SVD-2023-1105)"},{"cve":"CVE-2021-22570","qid":"671736","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-1814)"},{"cve":"CVE-2021-22570","qid":"671743","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-1797)"},{"cve":"CVE-2021-22570","qid":"671780","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-1851)"},{"cve":"CVE-2021-22570","qid":"671792","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-1875)"},{"cve":"CVE-2021-22570","qid":"672024","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-2232)"},{"cve":"CVE-2021-22570","qid":"672075","title":"EulerOS Security Update for protobuf (EulerOS-SA-2022-2279)"},{"cve":"CVE-2021-22570","qid":"751872","title":"OpenSUSE Security Update for protobuf (openSUSE-SU-2022:0823-1)"},{"cve":"CVE-2021-22570","qid":"751955","title":"OpenSUSE Security Update for protobuf (openSUSE-SU-2022:1040-1)"},{"cve":"CVE-2021-22570","qid":"751984","title":"SUSE Enterprise Linux Security Update for protobuf (SUSE-SU-2022:1040-1)"},{"cve":"CVE-2021-22570","qid":"752664","title":"SUSE Enterprise Linux Security Update for protobuf (SUSE-SU-2022:1040-3)"},{"cve":"CVE-2021-22570","qid":"754157","title":"SUSE Enterprise Linux Security Update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, pyt (SUSE-SU-2023:2783-1)"},{"cve":"CVE-2021-22570","qid":"754878","title":"SUSE Enterprise Linux Security Update for grpc, protobuf, python-DEPRECATED, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, pyt (SUSE-SU-2023:2783-2)"},{"cve":"CVE-2021-22570","qid":"900627","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for protobuf (8349)"},{"cve":"CVE-2021-22570","qid":"902067","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9830)"},{"cve":"CVE-2021-22570","qid":"902376","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9830-1)"},{"cve":"CVE-2021-22570","qid":"940751","title":"AlmaLinux Security Update for protobuf (ALSA-2022:7464)"},{"cve":"CVE-2021-22570","qid":"940830","title":"AlmaLinux Security Update for protobuf (ALSA-2022:7970)"},{"cve":"CVE-2021-22570","qid":"960304","title":"Rocky Linux Security Update for protobuf (RLSA-2022:7464)"},{"cve":"CVE-2021-22570","qid":"960471","title":"Rocky Linux Security Update for protobuf (RLSA-2022:7970)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@google.com","ID":"CVE-2021-22570","STATE":"PUBLIC","TITLE":"Nullptr Dereference in Protobuf"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Protobuf","version":{"version_data":[{"version_affected":"<","version_value":"3.15.0"}]}}]},"vendor_name":"Google LLC"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-476 NULL Pointer Dereference"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0","name":"https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0"},{"refsource":"FEDORA","name":"FEDORA-2022-ffe4a1cedd","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/"},{"refsource":"FEDORA","name":"FEDORA-2022-2d3e6eb9e4","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/"},{"refsource":"FEDORA","name":"FEDORA-2022-fedff53e4e","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/"},{"refsource":"FEDORA","name":"FEDORA-2022-486d5f349d","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/"},{"refsource":"FEDORA","name":"FEDORA-2022-d1a15f9cdb","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/"},{"refsource":"FEDORA","name":"FEDORA-2022-49b52819a4","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/"},{"refsource":"FEDORA","name":"FEDORA-2022-57923346cf","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","refsource":"MISC","name":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20220429-0005/","url":"https://security.netapp.com/advisory/ntap-20220429-0005/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20230418 [SECURITY] [DLA 3393-1] protobuf security update","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html"}]},"source":{"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2022-01-26 14:15:00","lastModifiedDate":"2023-11-07 03:30:00","problem_types":["CWE-476"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*","versionEndExcluding":"3.15.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*","versionEndIncluding":"8.0.28","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"22570","Ordinal":"197275","Title":"CVE-2021-22570","CVE":"CVE-2021-22570","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"22570","Ordinal":"1","NoteData":"Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"22570","Ordinal":"2","NoteData":"2022-01-26","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"22570","Ordinal":"3","NoteData":"2022-01-26","Type":"Other","Title":"Modified"}]}}}