{"schema_version":"1.9.0","id":"CVE-2024-2410","published":"2024-05-03T12:58:39.449Z","modified":"2026-08-12T03:51:33.202684086Z","related":["SUSE-SU-2025:20155-1","SUSE-SU-2025:20672-1"],"summary":"Use after free in C++ protobuf","details":"The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed. \n","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/protocolbuffers/protobuf","events":[{"introduced":"a847a8dc4ba1d99e7ba917146c84438b4de7d085"},{"fixed":"6b5d8db01fe47478e8d400f550e797e6230d464e"}],"database_specific":{"cpe":"cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.22.0"},{"fixed":"4.25.0"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2410.json"}}],"references":[{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/releases/tag/v25.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2410.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2410"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2410.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"}]}