protobuf 3.21.12-ok3 source package in openKylin
Changelog
protobuf (3.21.12-ok3) huanghe; urgency=high
* Security update. Backport the fixes from Debian 3.21.12-11, -12, -14
and Ubuntu 3.21.12-15ubuntu1. They are applied directly to the source
tree to stay in line with this package's "3.0 (native)" source format.
* CVE-2024-7254 (Java Full/Lite): parsing the unknown fields of a crafted
message could recurse without bound and crash the process with a
StackOverflowError. Add a recursion depth counter and a limit
(DEFAULT_RECURSION_LIMIT = 100) in ArrayDecoders, MessageSchema,
MessageSetSchema, UnknownFieldSchema and CodedInputStream.
* CVE-2025-4565 (pure Python): data containing an arbitrary number of
recursive groups, recursive messages or a series of SGROUP tags could
exceed the Python recursion limit and be mis-parsed. Track the recursion
depth while decoding unknown fields and reject an unmatched end-group
tag. Affects internal/decoder.py, internal/python_message.py and
unknown_fields.py.
* CVE-2026-0994 (pure Python): nested google.protobuf.Any messages could
bypass the max_recursion_depth limit of
google.protobuf.json_format.ParseDict(), leading to a denial of service
via stack overflow. Route well-known type conversion through
ConvertMessage() so that the recursion depth is accounted for.
* Add loongarch64 support (GOOGLE_PROTOBUF_ARCH_LOONGARCH64) to
src/google/protobuf/stubs/platform_macros.h.
* src/google/protobuf/port_def.inc: enable PROTOBUF_MUSTTAIL only on the
primary target platforms (aarch64, x86_64), which fixes build failures
on other architectures (upstream issue #22367).
* Add regression tests: CodedInputStreamTest, LiteTest, the map and
map_lite test protos, internal/message_test and internal/json_format_test.
-- Openkylin Developers <email address hidden> Thu, 24 Sep 2026 16:40:31 +0800