Release date:
2026-08-28 18:16:32 UTC
Description:
* SECURITY UPDATE: Unbounded recursion when parsing nested groups in
protobuf-java
- debian/patches/CVE-2024-7254.patch: bound the depth of the
skipMessage()/skipField() recursion in CodedInputStream and of the
nested-group recursion in UnknownFieldSetLite with the existing
recursion limit, so a stream of nested SGROUP tags can no longer
exhaust the Java stack
- CVE-2024-7254
* SECURITY UPDATE: Nested Any messages bypass the JSON parser recursion
depth limit in python-protobuf
- debian/patches/CVE-2026-0994.patch: add max_recursion_depth accounting
to json_format and route nested well-known types in
_ConvertAnyMessage() through ConvertMessage() so the depth is tracked
- CVE-2026-0994
Updated packages:
-
libprotobuf-dev_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:952fbfb1df808e0579b639f95ad4a9324d1ed52e
-
libprotobuf-java_3.0.0-9.1ubuntu1.1+tuxcare.els1_all.deb
sha:eaa17560ea6e7ffd9a2d9ceeca3a1814427992d2
-
libprotobuf-lite10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:357f09e54e07248117b09f1d587f8c7c47f939ea
-
libprotobuf10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:d811b35bab38e7bebc1edfdf80fa600bf87c2615
-
libprotoc-dev_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:9c06cf00fa456112f5ff47672affd25842187107
-
libprotoc10_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:f688b9f1087cc44bfc4b3ee96c6d4966aac8eaba
-
protobuf-compiler_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:0dbf24717977c1e3b02b16b8d03c7312f3deb903
-
python-protobuf_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:67b563ed53a63c9dbb90d4d56a1b3b31426de4df
-
python3-protobuf_3.0.0-9.1ubuntu1.1+tuxcare.els1_amd64.deb
sha:09b9fae04a49c846ee997c61de01c64860563598
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.