Vulnerabilities > CVE-2021-22570 - NULL Pointer Dereference vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

Vulnerable Configurations

Part Description Count
Application
Google
94
Application
Oracle
749
Application
Netapp
5
OS
Debian
3
OS
Fedoraproject
3

Common Weakness Enumeration (CWE)

References