Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2021-22570
HistoryJan 26, 2022 - 2:15 p.m.

CVE-2021-22570

2022-01-2614:15:00
Alpine Linux Development Team
security.alpinelinux.org
46
nullptr dereference
proto symbol
parsing
upgrade
version 3.15.0
error message
unix

EPSS

0

Percentile

15.9%

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file’s name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

OSVersionArchitecturePackageVersionFilename
Alpine3.13-mainnoarchprotobuf= 3.13.0-r2UNKNOWN
Alpine3.12-mainnoarchprotobuf= 3.12.2-r0UNKNOWN