<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:22:36.908818+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7464</id>
    <title>ALSA-2022:7464 — Moderate: protobuf security update</title>
    <updated>2026-10-03T23:22:37.555983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: protobuf, AlmaLinux:8: protobuf-compiler, AlmaLinux:8: protobuf-devel, AlmaLinux:8: protobuf-lite, AlmaLinux:8: protobuf-lite-devel, AlmaLinux:8: python3-protobuf</p>
<p>The protobuf packages provide Protocol Buffers, Google's data interchange format. Protocol Buffers can encode structured data in an efficient yet extensible format, and provide a flexible, efficient, and automated mechanism for serializing structured data.</p>
<p>Security Fix(es):</p>
<p>* protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference (CVE-2021-22570)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03824</id>
    <title>bdu:2023-03824</title>
    <updated>2026-10-03T23:22:37.556060+00:00</updated>
    <content>bdu:2023-03824</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03824"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-22570</id>
    <title>Withdrawn: BELL-CVE-2021-22570 — CVE-2021-22570 does not affect BellSoft software</title>
    <updated>2026-10-03T23:22:37.556079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2021-22570</id>
    <title>BREW-duplicity-CVE-2021-22570</title>
    <updated>2026-10-03T23:22:37.556095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: duplicity</p>
<p>Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0956</id>
    <title>certfr-2023-avi-0956 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Splunk&lt;/span&gt;. Elles permettent…</title>
    <updated>2026-10-03T23:22:37.556116+00:00</updated>
    <content>certfr-2023-avi-0956</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ga54121</id>
    <title>CLEANSTART-2026-GA54121 — Security fix for CVE-2021-22570 applied in: apache-hive 4.0.0-r0, apache-hive 4.2.0-r0, spark-sc213-jdk17-py312 3.4.4-r…</title>
    <updated>2026-10-03T23:22:37.556132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-hive, CleanStart: spark-sc213-jdk17-py312</p>
<p>CVE-2021-22570 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ga54121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232103</id>
    <title>EUVD-2026-232103</title>
    <updated>2026-10-03T23:22:37.556156+00:00</updated>
    <content>EUVD-2026-232103</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22570</id>
    <title>fkie_cve-2021-22570</title>
    <updated>2026-10-03T23:22:37.556168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-77rm-9x9h-xj3g</id>
    <title>Withdrawn: GHSA-77rm-9x9h-xj3g — Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers</title>
    <updated>2026-10-03T23:22:37.556189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> NuGet: Google.Protobuf, Packagist: google/protobuf, Maven: com.google.protobuf:protobuf-java, Go: github.com/protocolbuffers/protobuf, PyPI: protobuf</p>
<p>### Withdrawn Advisory</p>
<p>This advisory has been withdrawn because the protobuf vulnerability comes from the compiler rather that the code. This link is maintained to preserve external references.</p>
<p>### Original Description</p>
<p>Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-77rm-9x9h-xj3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22570</id>
    <title>gsd-2021-22570</title>
    <updated>2026-10-03T23:22:37.556221+00:00</updated>
    <content>gsd-2021-22570</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-22570</id>
    <title>msrc_CVE-2021-22570 — Nullptr Dereference in Protobuf</title>
    <updated>2026-10-03T23:22:37.556233+00:00</updated>
    <content>msrc_CVE-2021-22570</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-2106</id>
    <title>OESA-2022-2106 — protobuf security update</title>
    <updated>2026-10-03T23:22:37.556248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: protobuf</p>
<p>Protocol Buffers (a.k.a., protobuf) are Google&amp;apos;s language-neutral, platform-neutral, extensible mechanism for serializing structured data. You can find protobuf&amp;apos;s documentation on the Google Developers site.

Security Fix(es):

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file&amp;apos;s name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.(CVE-2021-22570)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-2106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0823-1</id>
    <title>openSUSE-SU-2022:0823-1 — Security update for protobuf</title>
    <updated>2026-10-03T23:22:37.556271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for protobuf</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0823-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-48</id>
    <title>PYSEC-2022-48</title>
    <updated>2026-10-03T23:22:37.556287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: protobuf</p>
<p>Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-48"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:8847</id>
    <title>RHSA-2022:8847 — Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.4 (protobuf) security update</title>
    <updated>2026-10-03T23:22:37.556306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>protobuf: Incorrect parsing of nullchar in the proto symbol leads to Nullptr dereference</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:8847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1040-1</id>
    <title>SUSE-SU-2022:1040-1 — Security update for protobuf</title>
    <updated>2026-10-03T23:22:37.556322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for protobuf</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1040-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22570</id>
    <title>UBUNTU-CVE-2021-22570</title>
    <updated>2026-10-03T23:22:37.556336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: protobuf, Ubuntu:Pro:16.04:LTS: protobuf, Ubuntu:18.04:LTS: protobuf, Ubuntu:20.04:LTS: protobuf, Ubuntu:22.04:LTS: protobuf</p>
<p>Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0169</id>
    <title>WID-SEC-W-2022-0169 — Oracle MySQL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:22:37.556360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0169"/>
  </entry>
</feed>
