CVE-2022-3171 is a denial-of-service vulnerability affecting protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6, and 3.16.3, impacting products from fedoraproject and google. The vulnerability stems from a parsing issue with binary data where specific input can cause excessive object conversions, leading to long garbage collection pauses. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, requiring no user interaction, and primarily impacts availability. There is currently no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.16.3CPE matchmatch criteria | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* | ||
>= 3.17.0, < 3.19.6CPE matchmatch criteria | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* | ||
>= 3.20.0, < 3.20.3CPE matchmatch criteria | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* | ||
>= 3.21.0, < 3.21.7CPE matchmatch criteria | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* | ||
< 3.16.3CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3171
Sep 10, 2024Splunk User Behavior Analytics (UBA) Third-Party Package Updates
Jan 9, 2024protobuf-java: timeout in parser leads to DoS
Oct 12, 2022Memory handling vulnerability in ProtocolBuffers Java core and lite
Oct 11, 2022protobuf-java has a potential Denial of Service issue
Oct 4, 2022