[CLSA-2026:1787934757] Fix CVE(s): CVE-2024-7254, CVE-2026-0994
Type:
security
Severity:
Important
Release date:
2026-08-28 18:16:32 UTC
Description:
* SECURITY UPDATE: Unbounded recursion when parsing nested groups in protobuf-java - debian/patches/CVE-2024-7254.patch: bound the depth of the skipMessage()/skipField() recursion in CodedInputStream and of the nested-group recursion in UnknownFieldSetLite with the existing recursion limit, so a stream of nested SGROUP tags can no longer exhaust the Java stack - CVE-2024-7254 * SECURITY UPDATE: Nested Any messages bypass the JSON parser recursion depth limit in python-protobuf - debian/patches/CVE-2026-0994.patch: add max_recursion_depth accounting to json_format and route nested well-known types in _ConvertAnyMessage() through ConvertMessage() so the depth is tracked - CVE-2026-0994
Updated packages:
  • libprotobuf-dev_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:952fbfb1df808e0579b639f95ad4a9324d1ed52e
  • libprotobuf-java_3.0.0-9.1ubuntu1.1+tuxcare.els1_all.deb
    sha:eaa17560ea6e7ffd9a2d9ceeca3a1814427992d2
  • libprotobuf-lite10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:357f09e54e07248117b09f1d587f8c7c47f939ea
  • libprotobuf10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:d811b35bab38e7bebc1edfdf80fa600bf87c2615
  • libprotoc-dev_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:9c06cf00fa456112f5ff47672affd25842187107
  • libprotoc10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:f688b9f1087cc44bfc4b3ee96c6d4966aac8eaba
  • protobuf-compiler_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:0dbf24717977c1e3b02b16b8d03c7312f3deb903
  • python-protobuf_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:67b563ed53a63c9dbb90d4d56a1b3b31426de4df
  • python3-protobuf_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
    sha:09b9fae04a49c846ee997c61de01c64860563598
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.