« List of all CVEs

CVE-2021-22570

Nullptr Dereference in Protobuf

Published: 1/26/2022 Last updated: 4/21/2025 Reserved: 1/5/2021

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

CNA assigner: Google (14ed7db2-1595-443d-9d34-6215bf890778) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6.5 Medium CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (6)

conf-mysql conf-protoc conf-protoc-dev kinetic-client protocell riak-pb

Products affected (1)

Product Vendor Version
Protobuf Google LLC <= 4.14.*

References (22)