← Back

CVE-2021-22570

nvd nist
Published: Jan 26, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

Affected (13)

Products: Google: Protobuf · Debian: Debian Linux · Fedoraproject: Fedora · +2 more
Show all products
1 product
Protobuf
1 product
Debian Linux
1 product
Fedora
1 product
Mysql
4 products
Active Iq Unified Manager
Oncommand Insight
Oncommand Workflow Automation
Snapcenter
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.15.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Version 36
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.28
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
All versions
All versions

References (22)

Source: cve-coordination@google.com
Release NotesThird Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.