USN-8063-1: Protocol Buffers vulnerability
USN-8063-1: Protocol Buffers vulnerability
Publication date: 25 February 2026
Overview: Protocol Buffers could be made to consume resources if it received specially crafted input.
Packages
- protobuf - protocol buffers data serialization library
Details
It was discovered that Protocol Buffers incorrectly handled recursion when
the Python google.protobuf.json_format.ParseDict() function is being used.
An attacker could possibly use this issue to cause Protocol Buffers to
consume resources, resulting in a denial of service.
Update instructions
25.10 questing
libprotobuf32t64 – 3.21.12-11ubuntu3.1
python3-protobuf – 3.21.12-11ubuntu3.1
24.04 LTS noble
- libprotobuf32t64 – 3.21.12-8.2ubuntu0.3
- python3-protobuf – 3.21.12-8.2ubuntu0.3
22.04 LTS jammy
- libprotobuf23 – 3.12.4-1ubuntu7.22.04.6
- python3-protobuf – 3.12.4-1ubuntu7.22.04.6

