{"schema_version":"1.7.3","id":"GHSA-77rm-9x9h-xj3g","published":"2022-01-27T00:01:15Z","modified":"2026-02-04T03:11:46.835319Z","withdrawn":"2025-08-25T22:36:48Z","aliases":["CVE-2021-22570","PYSEC-2022-48"],"related":["CGA-mmq2-c642-63f5"],"summary":"Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers","details":"### Withdrawn Advisory\n\nThis advisory has been withdrawn because the protobuf vulnerability comes from the compiler rather that the code. This link is maintained to preserve external references.\n\n### Original Description\n\nNullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.","affected":[{"package":{"name":"Google.Protobuf","ecosystem":"NuGet","purl":"pkg:nuget/Google.Protobuf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.0"}]}],"versions":["0.0.1-test1","3.0.0","3.0.0-alpha4","3.0.0-beta2","3.0.0-beta3","3.0.0-beta4","3.1.0","3.10.0","3.10.0-rc1","3.10.1","3.11.0-rc1","3.11.0-rc2","3.11.1","3.11.2","3.11.3","3.11.4","3.12.0","3.12.0-rc1","3.12.0-rc2","3.12.1","3.12.2","3.12.3","3.12.4","3.13.0","3.13.0-rc3","3.14.0","3.14.0-rc1","3.14.0-rc2","3.14.0-rc3","3.15.0-rc1","3.15.0-rc2","3.2.0","3.2.0-rc1","3.2.0-rc2","3.3.0","3.4.0","3.4.1","3.5.0","3.5.1","3.6.0","3.6.1","3.7.0","3.8.0","3.9.0","3.9.0-rc1","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}},{"package":{"name":"google/protobuf","ecosystem":"Packagist","purl":"pkg:composer/google/protobuf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.0"}]}],"versions":["v3.1.0-alpha-1","v3.10.0","v3.10.0RC1","v3.11.0","v3.11.0RC1","v3.11.0RC2","v3.11.1","v3.11.2","v3.11.3","v3.11.4","v3.12.0","v3.12.0RC1","v3.12.0RC2","v3.12.1","v3.12.2","v3.12.4","v3.13.0","v3.13.0.1","v3.13.0RC3","v3.14.0","v3.14.0RC1","v3.14.0RC2","v3.14.0RC3","v3.15.0RC1","v3.15.0RC2","v3.2.0-alpha-1","v3.3.0","v3.3.0rc1","v3.3.1","v3.3.2","v3.4.0","v3.4.0rc1","v3.4.0rc2","v3.4.0rc3","v3.4.1","v3.5.0","v3.5.0.1","v3.5.1","v3.5.1.1","v3.5.2","v3.6.0","v3.6.0.1","v3.6.0rc1","v3.6.0rc2","v3.6.1","v3.6.1.1","v3.6.1.2","v3.6.1.3","v3.7.0","v3.7.0-rc.3","v3.7.0rc1","v3.7.0rc2","v3.7.1","v3.8.0","v3.8.0RC1","v3.9.0","v3.9.0RC1","v3.9.1","v3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}},{"package":{"name":"com.google.protobuf:protobuf-java","ecosystem":"Maven","purl":"pkg:maven/com.google.protobuf/protobuf-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.0"}]}],"versions":["2.0.1","2.0.3","2.1.0","2.2.0","2.3.0","2.4.0a","2.4.1","2.5.0","2.6.0","2.6.1","3.0.0","3.0.0-alpha-2","3.0.0-alpha-3","3.0.0-alpha-3.1","3.0.0-beta-1","3.0.0-beta-2","3.0.0-beta-3","3.0.0-beta-4","3.0.2","3.1.0","3.10.0","3.10.0-rc-1","3.11.0","3.11.0-rc-1","3.11.0-rc-2","3.11.1","3.11.3","3.11.4","3.12.0","3.12.0-rc-1","3.12.0-rc-2","3.12.1","3.12.2","3.12.4","3.13.0","3.13.0-rc-3","3.14.0","3.14.0-rc-1","3.14.0-rc-2","3.14.0-rc-3","3.15.0-rc-1","3.15.0-rc-2","3.2.0","3.2.0-rc.1","3.2.0rc2","3.3.0","3.3.1","3.4.0","3.5.0","3.5.1","3.6.0","3.6.1","3.7.0","3.7.0-rc1","3.7.1","3.8.0","3.8.0-rc-1","3.9.0","3.9.0-rc-1","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}},{"package":{"name":"github.com/protocolbuffers/protobuf","ecosystem":"Go","purl":"pkg:golang/github.com/protocolbuffers/protobuf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20210218195015-ae50d9b99025"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}},{"package":{"name":"protobuf","ecosystem":"PyPI","purl":"pkg:pypi/protobuf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.0"}]}],"versions":["2.0.0beta","2.0.3","2.3.0","2.4.1","2.5.0","2.6.0","2.6.1","3.0.0","3.0.0a2","3.0.0a3","3.0.0b1","3.0.0b1.post1","3.0.0b1.post2","3.0.0b2","3.0.0b2.post1","3.0.0b2.post2","3.0.0b3","3.0.0b4","3.1.0","3.1.0.post1","3.10.0","3.10.0rc1","3.11.0","3.11.0rc1","3.11.0rc2","3.11.1","3.11.2","3.11.3","3.12.0","3.12.0rc1","3.12.0rc2","3.12.1","3.12.2","3.12.4","3.13.0","3.13.0rc3","3.14.0","3.14.0rc1","3.14.0rc2","3.14.0rc3","3.15.0rc1","3.15.0rc2","3.2.0","3.2.0rc1","3.2.0rc1.post1","3.2.0rc2","3.3.0","3.4.0","3.5.0.post1","3.5.1","3.5.2","3.5.2.post1","3.6.0","3.6.1","3.7.0","3.7.0rc2","3.7.0rc3","3.7.1","3.8.0","3.8.0rc1","3.9.0","3.9.0rc1","3.9.1","3.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}},{"package":{"name":"github.com/protocolbuffers/protobuf","ecosystem":"Go","purl":"pkg:golang/github.com/protocolbuffers/protobuf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0"},{"fixed":"3.15.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-77rm-9x9h-xj3g/GHSA-77rm-9x9h-xj3g.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22570"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-77rm-9x9h-xj3g"},{"type":"PACKAGE","url":"https://github.com/protocolbuffers/protobuf"},{"type":"WEB","url":"https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/protobuf/PYSEC-2022-48.yaml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20220429-0005"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"database_specific":{"cwe_ids":["CWE-476"],"github_reviewed":true,"github_reviewed_at":"2022-02-03T22:48:51Z","nvd_published_at":"2022-01-26T14:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}