RHSA-2024:3433: Moderate: protobuf security update
Moderate: protobuf security update
Other sources
The protobuf packages provide Protocol Buffers, Google's data interchange format. Protocol Buffers can encode structured data in an efficient yet extensible format, and provide a flexible, efficient, and automated mechanism for serializing structured data.Security Fix(es): protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference (CVE-2021-22570) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3433?
The severity of RHSA-2024:3433 is classified as moderate.
How do I fix RHSA-2024:3433?
To fix RHSA-2024:3433, you should update the protobuf package to version 3.5.0-15.el8_6.
Which systems are affected by RHSA-2024:3433?
RHSA-2024:3433 affects multiple versions of Red Hat Enterprise Linux including x86_64, Power LE, ARM 64, and IBM z Systems.
What packages are impacted by RHSA-2024:3433?
The impacted packages by RHSA-2024:3433 include protobuf, protobuf-compiler, protobuf-lite, and their respective debug and development versions.
Is there a specific version I need to update to for RHSA-2024:3433?
Yes, you need to update to protobuf version 3.5.0-15.el8_6 to resolve the vulnerability described in RHSA-2024:3433.