Medium severity5.5NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026
CVE-2022-33070
CVE-2022-33070
Description
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:a:protobuf-c_project:protobuf-c:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- Protobuf-c/Protobuf-cdescription
- Range: =1.4.0
- osv-coords6 versionspkg:apk/chainguard/protobuf-cpkg:apk/chainguard/protobuf-c-compilerpkg:apk/chainguard/protobuf-c-devpkg:apk/wolfi/protobuf-cpkg:apk/wolfi/protobuf-c-compilerpkg:apk/wolfi/protobuf-c-dev
< 0+ 5 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
3- github.com/protobuf-c/protobuf-c/issues/506nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/protobuf-c/protobuf-c/pull/508nvdExploitIssue TrackingPatchThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFN2GHUEGTSHRD7J5PKQ5DRSJSEQ2IKN/nvd
News mentions
0No linked articles in our index yet.