SUSE alert openSUSE-SU-2026:20390-1 (protobuf)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:20390-1: moderate: Security update for protobuf | |
| Date: | Wed, 25 Mar 2026 17:52:08 +0100 | |
| Message-ID: | <20260325165208.292E9FDC8@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for protobuf ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20390-1 Rating: moderate References: * bsc#1244663 * bsc#1244918 * bsc#1257173 Cross-References: * CVE-2025-4565 * CVE-2026-0994 CVSS scores: * CVE-2025-4565 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4565 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0994 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0994 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for protobuf fixes the following issues: Security fixes: - CVE-2025-4565: Fixed parsing of untrusted Protocol Buffers data containing an arbitrary number of recursive groups or messages that could lead to crash due to RecursionError (bsc#1244663). - CVE-2026-0994: Fixed google.protobuf.Any recursion depth bypass in Python json_format.ParseDict (bsc#1257173). Other fixes: - Fixed import issues of reverse-dependency packages within the google namespace (bsc#1244918). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-408=1 Package List: - openSUSE Leap 16.0: libprotobuf-lite28_3_0-28.3-160000.3.1 libprotobuf28_3_0-28.3-160000.3.1 libprotoc28_3_0-28.3-160000.3.1 libutf8_range-28_3_0-28.3-160000.3.1 protobuf-devel-28.3-160000.3.1 protobuf-java-28.3-160000.3.1 protobuf-java-bom-28.3-160000.3.1 protobuf-java-javadoc-28.3-160000.3.1 protobuf-java-parent-28.3-160000.3.1 python313-protobuf-5.28.3-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-4565.html * https://www.suse.com/security/cve/CVE-2026-0994.html
