This update for protobuf fixes the following issues:
Security fixes:
- CVE-2025-4565: Fixed parsing of untrusted Protocol Buffers data containing an arbitrary number of recursive
groups or messages that could lead to crash due to RecursionError (bsc#1244663).
- CVE-2026-0994: Fixed google.protobuf.Any recursion depth bypass in Python json_format.ParseDict (bsc#1257173).
Other fixes:
- Fixed import issues of reverse-dependency packages within the google namespace (bsc#1244918).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-408=1
- openSUSE Leap 16.0:
libprotobuf-lite28_3_0-28.3-160000.3.1
libprotobuf28_3_0-28.3-160000.3.1
libprotoc28_3_0-28.3-160000.3.1
libutf8_range-28_3_0-28.3-160000.3.1
protobuf-devel-28.3-160000.3.1
protobuf-java-28.3-160000.3.1
protobuf-java-bom-28.3-160000.3.1
protobuf-java-javadoc-28.3-160000.3.1
protobuf-java-parent-28.3-160000.3.1
python313-protobuf-5.28.3-160000.3.1
* bsc#1244663
* bsc#1244918
* bsc#1257173
References:
* https://www.suse.com/security/cve/CVE-2025-4565.html
* https://www.suse.com/security/cve/CVE-2026-0994.html
Get the latest Linux and open source security news straight to your inbox.