CVE-2021-22570

MEDIUM

Google Protobuf < 3.15.0 - Null Pointer Dereference via Proto Symbol Parsing

Title source: llm
STIX 2.1

Description

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

References (11)

Core 11
Core References

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 35.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (17)
com.google.protobuf/protobuf-java 0 - 3.15.0Maven
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
fedoraproject/fedora 36
google/protobuf < 3.15.0
google/protobuf 0 - 3.15.0Packagist
netapp/active_iq_unified_manager (2 CPE variants)
... and 7 more
Published Jan 26, 2022
Tracked Since Feb 18, 2026