Back to bug 2184161

Who When What Removed Added
Chess Hazlett 2023-04-03 19:35:23 UTC Summary CVE-2022-3509 protobuf-java: parsing issue leads to DoS CVE-2022-3509 protobuf-java: Textformat parsing issue leads to DoS
Chess Hazlett 2023-04-03 19:52:43 UTC CC asoldano, ataylor, bbaranow, bmaxwell, brian.stansberry, cdewolf, darran.lofthouse, dkreling, dosoudil, fjuma, ivassile, iweiss, jross, lgao, mokumar, mosmerov, msochure, msvehla, nwallace, pmackay, rstancel, smaestri, tom.jenkinson
Chess Hazlett 2023-04-03 20:13:40 UTC CC aileenc, alampare, alazarot, anstephe, avibelli, bgeorges, boliveir, clement.escoffier, dandread, dhanak, drichtar, emingora, eric.wittmann, fmongiar, gjospin, gmalinko, gsmet, hamadhan, ibek, janstey, jmartisk, jnethert, jolee, jpavlik, jpechane, jrokos, jschatte, jstastny, kverlaen, lbacciot, lthon, max.andersen, mnovotny, pantinor, pdelbell, pdrozd, peholase, pgallagh, probinso, pskopek, rguimara, rjohnson, rowaters, rrajasek, rruss, rsvoboda, sbiarozk, sdouglas, sthorger
Chess Hazlett 2023-04-03 20:24:50 UTC CC jcantril, mizdebsk, periklis
Paige Jung 2023-04-03 20:29:18 UTC Doc Text Textformat in protobuf-java core can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted between mutable and immutable forms, resulting in potentially long garbage collection pauses. A flaw was found in Textformat in protobuf-java core that can lead to a denial of service. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields can cause objects to convert between mutable and immutable forms, resulting in long garbage collection pauses.
errata-xmlrpc 2023-04-18 19:01:29 UTC Link ID Red Hat Product Errata RHSA-2023:1855
Red Hat Bugzilla 2023-05-15 18:03:51 UTC CC rrajasek
Red Hat Bugzilla 2023-05-16 09:27:31 UTC CC mokumar
Avinash Hanwate 2023-05-24 04:29:59 UTC CC abenaiss, ellin, scorneli, shbose
Avinash Hanwate 2023-05-24 04:36:06 UTC Depends On 2209567
errata-xmlrpc 2023-06-27 11:29:10 UTC Link ID Red Hat Product Errata RHSA-2023:3815
Product Security DevOps Team 2023-06-27 15:43:41 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2023-06-27 15:43:41 UTC

Back to bug 2184161