CVE-2025-53605: Input Validation

Published Mar 7, 2025
·
Updated

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-2gh3-rmm4-6rq5. This link is maintained to preserve external references.

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::codedinputstream::CodedInputStream::skipgroup parsing of unknown fields in untrusted input.

Other sources

Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.

This allows an attacker to cause a stack overflow when parsing the message on untrusted data.

GitHub

Affected Software

14 affected componentsFixes available
protobuf protobuf crate<3.7.2
rust/protobuf<3.7.2
3.7.2
Microsoft cbl2 rust 1.72.0-10
Microsoft azl3 rust 1.86.0-4
Microsoft cbl2 rust 1.72.0-11
Microsoft azl3 kata-containers 3.18.0.kata0-3
Microsoft azl3 rust 1.75.0-17
Microsoft cbl2 kata-containers 3.2.0.azl2-7
Microsoft azl3 kata-containers-cc 3.15.0.aks0-5
Microsoft cbl2 rust 1.72.0-10
Microsoft cbl2 kata-containers-cc 3.2.0.azl2-8
Microsoft cbl2 kata-containers-cc 3.2.0.azl2-7
Microsoft cbl2 kata-containers 3.2.0.azl2-6
Microsoft azl3 kata-containers-cc 3.15.0.aks0-4

Event History

Mar 7, 2025
Advisory Published
via GitHub·08:02 PM
Data Sourced
via GitHub·08:02 PM
DescriptionWeaknessAffected Software
Jul 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Data Sourced
via GitHub·03:30 AM
Severity
Updated
via GitHub·03:30 AM
DescriptionWeakness
Aug 1, 2025
Withdrawn
via GitHub·07:17 PM
Sep 4, 2025
Data Sourced
via Microsoft·03:26 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·03:26 AM
SeverityAffected Software
Updated
via Microsoft·03:26 AM
Affected Software
Updated
via Microsoft·10:26 AM
Affected Software
Updated
via Microsoft·10:26 AM
SeverityAffected Software
Updated
via Microsoft·10:26 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-53605?

CVE-2025-53605 is classified as a medium severity vulnerability due to its potential for causing denial of service through uncontrolled recursion.

2

How do I fix CVE-2025-53605?

To fix CVE-2025-53605, upgrade the protobuf crate to version 3.7.2 or later.

3

What software is affected by CVE-2025-53605?

CVE-2025-53605 affects the protobuf crate for Rust versions earlier than 3.7.2.

4

What kind of attack does CVE-2025-53605 allow?

CVE-2025-53605 allows attackers to cause uncontrolled recursion when processing untrusted input, potentially leading to denial of service.

5

Is CVE-2025-53605 specific to a particular programming language?

Yes, CVE-2025-53605 specifically affects the Rust programming language through the protobuf crate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203