HomeDefectsLIN1021-22630
Acknowledged

LIN1021-22630 : Security Advisory - protobuf - CVE-2026-6409

Created: Apr 17, 2026    Updated: Apr 24, 2026
Found In Version: 10.21.20.2
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability.