CVE-2024-7254
Publication date 19 September 2024
Last updated 9 July 2025
Ubuntu priority
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Status
Package | Ubuntu Release | Status |
---|---|---|
protobuf | 25.04 plucky |
Fixed 3.21.12-10ubuntu0.1
|
24.04 LTS noble |
Fixed 3.21.12-8.2ubuntu0.1
|
|
22.04 LTS jammy |
Fixed 3.12.4-1ubuntu7.22.04.2
|
|
20.04 LTS focal |
Vulnerable
|
|
18.04 LTS bionic |
Vulnerable
|
|
16.04 LTS xenial |
Vulnerable
|
|
14.04 LTS trusty |
Vulnerable
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-7435-1
- Protocol Buffers vulnerability
- 14 April 2025
- USN-7629-1
- Protocol Buffers vulnerabilities
- 9 July 2025
- USN-7629-2
- Protocol Buffers vulnerabilities
- 2 September 2025