PT-2025-25564 · Protobuf+6 · Protobuf+6

CVE-2025-4565

·

Publicado

2025-05-14

·

Atualizado

2026-07-09

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Protobuf versions prior to 6.31.1
Description The issue affects projects that use the Protobuf Pure-Python backend to parse untrusted Protocol Buffers data. This data can contain an arbitrary number of recursive groups, recursive messages, or a series of SGROUP tags, which can cause the application to exceed the Python recursion limit. As a result, this can lead to a Denial of Service by crashing the application with a RecursionError.
Recommendations For versions prior to 6.31.1, upgrade to version 6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901 to resolve the issue.

Exploit

Correção

DoS

Uncontrolled Recursion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-64116
AZL-64145
BDU:2025-10926
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2025-4565
ECHO-869D-3EC4-EFD0
GHSA-8QVM-5X2C-J2W7
OESA-2025-1713
OESA-2025-1714
OESA-2025-1798
OESA-2025-1799
OESA-2025-1800
OESA-2025-1801
OPENSUSE-SU-2025:15265-1
OPENSUSE-SU-2026:20390-1
PYSEC-2026-1806
RHSA-2026:1249
SUSE-SU-2025:02309-1
SUSE-SU-2025:02310-1
SUSE-SU-2025:02311-1
SUSE-SU-2025:20514-1
SUSE-SU-2025:20672-1
SUSE-SU-2025:3722-1
SUSE-SU-2025_02309-1
SUSE-SU-2025_02310-1
SUSE-SU-2025_02311-1
SUSE-SU-2025_3722-1
SUSE-SU-2026:1653-1
SUSE-SU-2026:20753-1
SUSE-SU-2026:20907-1
USN-7629-1
USN-7629-2

Produtos afetados

Astra Linux
Debian
Linuxmint
Protobuf
Red Os
Suse
Ubuntu