A
ny project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
References
| Link | Resource |
|---|---|
| https://github.com/protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa | Patch |
| https://security.netapp.com/advisory/ntap-20241213-0010/ | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20250418-0006/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
26 Sep 2025, 17:10
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Google protobuf
Netapp ontap Tools Google protobuf-javalite Google protobuf-kotlin Netapp bluexp Google protobuf-kotlin-lite Google protobuf-java Netapp active Iq Unified Manager Netapp |
|
| CWE | CWE-787 CWE-400 CWE-674 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:*:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* |
|
| References | () https://github.com/protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa - Patch | |
| References | () https://security.netapp.com/advisory/ntap-20241213-0010/ - Third Party Advisory | |
| References | () https://security.netapp.com/advisory/ntap-20250418-0006/ - Third Party Advisory |
19 Apr 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Dec 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Sep 2024, 12:30
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 Sep 2024, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-09-19 01:15
Updated : 2025-09-26 17:10
NVD link : CVE-2024-7254
Mitre link : CVE-2024-7254
CVE.ORG link : CVE-2024-7254
JSON object : View
Products Affected