Wind River Support Network

HomeDefectsLIN1021-11439
Fixed

LIN1021-11439 : Security Advisory - protobuf - CVE-2024-7254

Created: Sep 19, 2024    Updated: May 26, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.

CREATE(Triage):(User=admin) CVE-2024-7254 (https://nvd.nist.gov/vuln/detail/CVE-2024-7254)

CVEs


Live chat
Online