Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Protocol Buffers could be made to consume resources if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8063-1 February 25, 2026 protobuf vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Protocol Buffers could be made to consume resources if it received specially crafted input. Software Description: - protobuf: protocol buffers data serialization library Details: It was discovered that Protocol Buffers incorrectly handled recursion when the Python google.protobuf.json_format.ParseDict() function is being used. An attacker could possibly use this issue to cause Protocol Buffers to consume resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libprotobuf32t64 3.21.12-11ubuntu3.1 python3-protobuf 3.21.12-11ubuntu3.1 Ubuntu 24.04 LTS libprotobuf32t64 3.21.12-8.2ubuntu0.3 python3-protobuf 3.21.12-8.2ubuntu0.3 Ubuntu 22.04 LTS libprotobuf23 3.12.4-1ubuntu7.22.04.6 python3-protobuf 3.12.4-1ubuntu7.22.04.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8063-1 CVE-2026-0994 Package Information: https://launchpad.net/ubuntu/+source/protobuf/3.21.12-11ubuntu3.1 https://launchpad.net/ubuntu/+source/protobuf/3.21.12-8.2ubuntu0.3 https://launchpad.net/ubuntu/+source/protobuf/3.12.4-1ubuntu7.22.04.6 . Addressing resource consumption issues in Protocol Buffers on Ubuntu through security updates for affected releases.. Protocol Buffers Denial Of Service Ubuntu Security Update. . Severity: Important. LinuxSecurity.com Team
Protocol Buffers could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7629-2 September 02, 2025 protobuf vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Protocol Buffers could be made to crash if it received specially crafted input. Software Description: - protobuf: protocol buffers data serialization library Details: USN-7435-1 and USN-7629-1 fixed vulnerabilities in Protocol Buffers for several releases of Ubuntu. This update provides the corresponding fixes for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Protocol Buffers incorrectly handled memory when receiving malicious input using the Python bindings. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-4565) It was discovered that Protocol Buffers incorrectly handled memory when receiving malicious input using the Java bindings. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.04. (CVE-2024-7254) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libprotobuf-java 3.6.1.3-2ubuntu5.2+esm2 Available with Ubuntu Pro python3-protobuf 3.6.1.3-2ubuntu5.2+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libprotobuf-java 3.0.0-9.1ubuntu1.1+esm3 Available with Ubuntu Pro python3-protobuf 3.0.0-9.1ubuntu1.1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libprotobuf-java 2.6.1-1.3ubuntu0.1~esm4 Available with Ubuntu Pro python-protobuf 2.6.1-1.3ubuntu0.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7629-2 https://ubuntu.com/security/notices/USN-7629-1 CVE-2024-7254, CVE-2025-4565 . Stay informed about crucial Protocol Buffers updates for Ubuntu 20.04, 18.04, and 16.04 that tackle Denial of Service (DoS) vulnerabilities and safeguard your system. Denial of Service, Protocol Buffers, Ubuntu Fixes. . Severity: Important. LinuxSecurity.com Team
Protocol Buffers could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7629-2 September 02, 2025 protobuf vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Protocol Buffers could be made to crash if it received specially crafted input. Software Description: - protobuf: protocol buffers data serialization library Details: USN-7435-1 and USN-7629-1 fixed vulnerabilities in Protocol Buffers for several releases of Ubuntu. This update provides the corresponding fixes for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Protocol Buffers incorrectly handled memory when receiving malicious input using the Python bindings. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-4565) It was discovered that Protocol Buffers incorrectly handled memory when receiving malicious input using the Java bindings. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.04. (CVE-2024-7254) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libprotobuf-java 3.6.1.3-2ubuntu5.2+esm2 Available with Ubuntu Pro python3-protobuf 3.6.1.3-2ubuntu5.2+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libprotobuf-java 3.0.0-9.1ubuntu1.1+esm3 Available with Ubuntu Pro python3-protobuf 3.0.0-9.1ubuntu1.1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libprotobuf-java 2.6.1-1.3ubuntu0.1~esm4 Available with Ubuntu Pro python-protobuf 2.6.1-1.3ubuntu0.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7629-2 https://ubuntu.com/security/notices/USN-7629-1 CVE-2024-7254, CVE-2025-4565 . Immediate action required for Protocol Buffers on Ubuntu versions 16.04, 18.04, and 20.04 to mitigate potential denial-of-service vulnerabilities.. Protocol Buffers Security, Ubuntu Vulnerabilities, Denial of Service Update. . Severity: Important. LinuxSecurity.com Team
Protocol Buffers could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7435-1 April 14, 2025 protobuf vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Protocol Buffers could be made to crash if it received specially crafted input. Software Description: - protobuf: protocol buffers data serialization library Details: It was discovered that Protocol Buffers incorrectly handled memory when receiving malicious input using the Java bindings. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libprotobuf-java 3.21.12-9ubuntu1.1 Ubuntu 24.04 LTS libprotobuf-java 3.21.12-8.2ubuntu0.1 Ubuntu 22.04 LTS libprotobuf-java 3.12.4-1ubuntu7.22.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7435-1 CVE-2024-7254 Package Information: https://launchpad.net/ubuntu/+source/protobuf/3.21.12-9ubuntu1.1 https://launchpad.net/ubuntu/+source/protobuf/3.21.12-8.2ubuntu0.1 https://launchpad.net/ubuntu/+source/protobuf/3.12.4-1ubuntu7.22.04.2 . Be aware of potential failures in Protocol Buffers when dealing with specially designed input in Ubuntu versions. Ensure that your system is up to date.. Ubuntu protocol buffers, denial of service, software update, security advisory, malicious input. . Severity: Critical. LinuxSecurity.com Team
Contains updates to address CVE-2022-{28357,41717}. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f122ea1b3e 2023-10-04 15:50:14.488468 -------------------------------------------------------------------------------- Name : golang-google-protobuf Product : Fedora 38 Version : 1.31.0 Release : 4.fc38 URL : https://github.com/protocolbuffers/protobuf-go Summary : Go support for Google's protocol buffers Description : Go support for Google's protocol buffers. -------------------------------------------------------------------------------- Update Information: Contains updates to address CVE-2022-{28357,41717} -------------------------------------------------------------------------------- ChangeLog: * Sun Sep 24 2023 Mikel Olasagasti Uranga - 1.31.0-4 - Add obsolete on removed goaltipath compat package * Sun Sep 24 2023 Mikel Olasagasti Uranga - 1.31.0-3 - Revert adding goaltipath * Wed Sep 13 2023 Mark E. Fuller - 1.31.0-2 - Update golang-google-protobuf.spec - add deprecated altpath * Sat Sep 9 2023 Mark E. Fuller - 1.31.0-1 - update to v1.31.0, close rhbz#2176730, rhbz#2171555, rhbz#2225889 * Thu Jul 20 2023 Fedora Release Engineering - 1.28.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 1.28.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f122ea1b3e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several security issues were fixed in Protocol Buffers.. =========================================================================Ubuntu Security Notice USN-5945-1 March 13, 2023 protobuf vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 14.04 ESM Summary: Several security issues were fixed in Protocol Buffers. Software Description: - protobuf: protocol buffers C++ library (development files) Details: It was discovered that Protocol Buffers did not properly validate field com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could possibly use this issue to perform a denial of service attack. This issue only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569) It was discovered that Protocol Buffers did not properly parse certain symbols. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. (CVE-2021-22570) It was discovered that Protocol Buffers did not properly manage memory when parsing specifically crafted messages. An attacker could possibly use this issue to cause applications using protobuf to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-1941) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libprotobuf-java 3.12.4-1ubuntu7.22.10.1 libprotobuf-lite23 3.12.4-1ubuntu7.22.10.1 libprotobuf23 3.12.4-1ubuntu7.22.10.1 libprotoc23 3.12.4-1ubuntu7.22.10.1 protobuf-compiler 3.12.4-1ubuntu7.22.10.1 python3-protobuf 3.12.4-1ubuntu7.22.10.1 Ubuntu 22.04 LTS: libprotobuf-java 3.12.4-1ubuntu7.22.04.1 libprotobuf-lite23 3.12.4-1ubuntu7.22.04.1 libprotobuf23 3.12.4-1ubuntu7.22.04.1 libprotoc23 3.12.4-1ubuntu7.22.04.1 protobuf-compiler 3.12.4-1ubuntu7.22.04.1 python3-protobuf 3.12.4-1ubuntu7.22.04.1 Ubuntu 20.04 LTS: libprotobuf-lite17 3.6.1.3-2ubuntu5.2 libprotoc-dev 3.6.1.3-2ubuntu5.2 libprotoc17 3.6.1.3-2ubuntu5.2 protobuf-compiler 3.6.1.3-2ubuntu5.2 python-protobuf 3.6.1.3-2ubuntu5.2 python3-protobuf 3.6.1.3-2ubuntu5.2 Ubuntu 18.04 LTS: libprotobuf-lite10 3.0.0-9.1ubuntu1.1 libprotobuf10 3.0.0-9.1ubuntu1.1 libprotoc10 3.0.0-9.1ubuntu1.1 protobuf-compiler 3.0.0-9.1ubuntu1.1 python-protobuf 3.0.0-9.1ubuntu1.1 python3-protobuf 3.0.0-9.1ubuntu1.1 Ubuntu 14.04 ESM: libprotobuf-lite8 2.5.0-9ubuntu1+esm1 libprotobuf8 2.5.0-9ubuntu1+esm1 libprotoc8 2.5.0-9ubuntu1+esm1 protobuf-compiler 2.5.0-9ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5945-1 CVE-2021-22569, CVE-2021-22570, CVE-2022-1941 Package Information: https://launchpad.net/ubuntu/+source/protobuf/3.12.4-1ubuntu7.22.10.1 https://launchpad.net/ubuntu/+source/protobuf/3.12.4-1ubuntu7.22.04.1 https://launchpad.net/ubuntu/+source/protobuf/3.6.1.3-2ubuntu5.2 https://launchpad.net/ubuntu/+source/protobuf/3.0.0-9.1ubuntu1.1 . Several vulnerabilities in Protocol Buffers addressed in Ubuntu, safeguarding against possible DoS incidents. Ensure your system is updated for enhanced protection.. Ubuntu, Protocol Buffers, DoS Attack, Security Update. . Severity: Critical. LinuxSecurity.com Team
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-google-protobuf Product : Fedora 36 Version : 1.27.1 Release : 6.fc36 URL : https://github.com/protocolbuffers/protobuf-go Summary : Go support for Google's protocol buffers Description : Go support for Google's protocol buffers. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 1.27.1-6 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.