Security update for protobuf
This update for protobuf fixes the following issues: - CVE-2024-2410: Use after free when parsing JSON from a stream (bsc#1223947). - CVE-2024-7254: StackOverflow vulnerability in Protocol Buffers (bsc#1230778). - CVE-2025-4565: Parsing of untrusted Protocol Buffers data containing an arbitrary number of recursive groups or messages can lead to crash due to RecursionError (bsc#1244663).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for protobuf fixes the following issues: - CVE-2024-2410: Use after free when parsing JSON from a stream (bsc#1223947). - CVE-2024-7254: StackOverflow vulnerability in Protocol Buffers (bsc#1230778). - CVE-2025-4565: Parsing of untrusted Protocol Buffers data containing an arbitrary number of recursive groups or messages can lead to crash due to RecursionError (bsc#1244663).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1223947
- https://bugzilla.suse.com/1230778
- https://bugzilla.suse.com/1244663
- https://www.suse.com/security/cve/CVE-2024-2410
- https://www.suse.com/security/cve/CVE-2024-7254
- https://www.suse.com/security/cve/CVE-2025-4565
- https://www.suse.com/support/update/announcement/2025/suse-su-202520672-1/