Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-22570

22
FAUCET Score

CVE-2021-22570 describes a null pointer dereference vulnerability affecting products from Debian, Fedora Project, Google, NetApp, and Oracle, caused by incorrect parsing of proto symbols containing null characters. This vulnerability has a medium severity CVSS score of 5.5, indicating a local attack vector with low complexity, requiring low privileges and no user interaction, leading to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.15.0CPE matchmatch criteria
cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.66%
Probability of exploitation in next 30 days
EPSS Percentile
84.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0266 is in the 99th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

composerpatch availablevia ghsa
Product: google/protobufFixed in: 3.15.0
gopatch availablevia ghsa
Product: github.com/protocolbuffers/protobufFixed in: 0.0.0-20210218195015-ae50d9b99025
gopatch availablevia ghsa
Product: github.com/protocolbuffers/protobufFixed in: 3.15.0
mavenpatch availablevia ghsa
Product: com.google.protobuf:protobuf-javaFixed in: 3.15.0
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.0.29-1
microsoftpatch availablevia msrc
Product: cm1 protobuf 3.14.0-1 on CBL Mariner 1.0Fixed in: 3.14.0-1
microsoftpatch availablevia msrc
Product: cbl2 mysql 8.0.29-1 on CBL Mariner 2.0Fixed in: 8.0.29-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.0.29-1
microsoftpatch availablevia msrc
Product: 18464-16820Fixed in: 3.14.0-1
microsoftpatch availablevia msrc
Product: 18714-16823Fixed in: 8.0.29-1
nugetpatch availablevia ghsa
Product: Google.ProtobufFixed in: 3.15.0
pippatch availablevia ghsa
Product: protobufFixed in: 3.15.0
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: protobuf-0:3.6.1-6.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: protobuf-0:3.6.1-6.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: protobuf-0:3.14.0-13.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: protobuf-0:3.5.0-15.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: protobuf-0:3.5.0-15.el8
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 9.0.7, 9.1.2
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-kuryr-controller-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-kuryr-cni-rhel8

Vendor Advisories (5)

zimbrallm-zimbra-eff41b993417b303HIGH

November 2023 Third Party Package updates in Splunk Enterprise

Nov 16, 2023
microsoft2022-Jun/CVE-2021-22570

CVE-2021-22570

Jun 14, 2022
nugetGHSA-77rm-9x9h-xj3ghigh

Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers

Jan 27, 2022
redhatCVE-2021-22570Moderate

protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference

Jan 26, 2022
microsoft2022-Jan/CVE-2021-22570Moderate

Nullptr Dereference in Protobuf

Jan 11, 2022

References

github.com / protocolbuffers/protobuf/releases/tag/v3.15.0
Release NotesThird Party Advisory
lists.debian.org / debian-lts-announce/2023/04/msg00019.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP
security.netapp.com / advisory/ntap-20220429-0005
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
Third Party Advisory