UbuntuUpdates.org

Package "protobuf"

Name: protobuf

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • protocol buffers C++ library (development files) and proto files
  • protocol buffers C++ library (lite version)
  • protocol buffers C++ library
  • protocol buffers compiler library (development files)

Latest version: 3.21.12-11ubuntu3.1
Release: questing (25.10)
Level: updates
Repository: main

Links



Other versions of "protobuf" in Questing

Repository Area Version
base main 3.21.12-11ubuntu3
base universe 3.21.12-11ubuntu3
security main 3.21.12-11ubuntu3.1
security universe 3.21.12-11ubuntu3.1
updates universe 3.21.12-11ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.21.12-11ubuntu3.1 2026-02-25 19:07:55 UTC

  protobuf (3.21.12-11ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: max_recursion_depth limit can be bypassed in
    google.protobuf.json_format.ParseDict()
    - debian/patches/CVE-2026-0994.patch: fix Any recursion depth bypass in
      Python in python/google/protobuf/internal/json_format_test.py,
      python/google/protobuf/json_format.py.
    - CVE-2026-0994

 -- Marc Deslauriers <email address hidden> Fri, 20 Feb 2026 14:33:28 -0500

CVE-2026-0994 A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypas



About   -   Send Feedback to @ubuntu_updates