← Back

CVE-2022-3171

nvd nist
Published: Oct 12, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

Affected (21)

5 products
Google Protobuf
Protobuf Java
Protobuf Javalite
Protobuf Kotlin
Protobuf Kotlin Lite
1 product
Fedora
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Google
Before 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Google
Before 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Google
Before 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Google
Before 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Google
Before 3.16.3
From 3.17.0 to 3.19.6
From 3.20.0 to 3.20.3
From 3.21.0 to 3.21.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 37

Timeline

No history available yet.