UBUNTU-CVE-2024-24786

Source
https://ubuntu.com/security/CVE-2024-24786
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-24786
Upstream
Downstream
Related
Published
2024-03-05T23:15:00Z
Modified
2026-02-04T04:38:17.533180Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

References

Affected packages

Ubuntu:20.04:LTS
google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent@20250115.01-0ubuntu1~20.04.0?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*
20210219.00-0ubuntu1~20.04.0
20210608.*
20210608.1-0ubuntu1~20.04.0
20210608.1-0ubuntu1~20.04.1
20220824.*
20220824.00-0ubuntu1~20.04.1
20230504.*
20230504.00-0ubuntu1~20.04.0
20240320.*
20240320.00-0ubuntu1~20.04.0
20240320.00-0ubuntu1~20.04.1
20240524.*
20240524.03-0ubuntu2~20.04.0
20240926.*
20240926.03-0ubuntu1~20.04.0
20250115.*
20250115.01-0ubuntu1~20.04.0

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20250115.01-0ubuntu1~20.04.0",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
Ubuntu:22.04:LTS
golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf@1.27.1-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.25.0+git20201208.160c747-1
1.27.1-1
1.27.1-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.27.1-1ubuntu0.1",
            "binary_name": "golang-google-protobuf-dev"
        },
        {
            "binary_version": "1.27.1-1ubuntu0.1",
            "binary_name": "protoc-gen-go"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent@20231004.02-0ubuntu1~22.04.4?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20231004.02-0ubuntu1~22.04.4

Affected versions

20210629.*
20210629.00-0ubuntu1
20210629.00-0ubuntu2
20220104.*
20220104.00-0ubuntu1
20220104.00-0ubuntu2
20220622.*
20220622.00-0ubuntu2~22.04.0
20220622.00-0ubuntu2~22.04.1
20230426.*
20230426.00-0ubuntu2~22.04.0
20231004.*
20231004.02-0ubuntu1~22.04.1
20231004.02-0ubuntu1~22.04.2
20231004.02-0ubuntu1~22.04.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "20231004.02-0ubuntu1~22.04.4",
            "binary_name": "google-guest-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent@20230504.00-0ubuntu1~22.04.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20230504.00-0ubuntu1~22.04.1

Affected versions

20210608.*
20210608.1-0ubuntu1
20210608.1-0ubuntu2
20210608.1-0ubuntu3
20220824.*
20220824.00-0ubuntu1~22.04.1
20220824.00-0ubuntu1~22.04.2
20230504.*
20230504.00-0ubuntu1~22.04.0

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "20230504.00-0ubuntu1~22.04.1",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
Ubuntu:24.04:LTS
golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf@1.32.0-1ubuntu0.3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.28.1-3build1
1.31.0-1
1.32.0-1
1.32.0-1ubuntu0.1
1.32.0-1ubuntu0.2
1.32.0-1ubuntu0.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.32.0-1ubuntu0.3",
            "binary_name": "golang-google-protobuf-dev"
        },
        {
            "binary_version": "1.32.0-1ubuntu0.3",
            "binary_name": "protoc-gen-go"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent@20240213.00-0ubuntu3.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240213.00-0ubuntu3.1

Affected versions

20230426.*
20230426.00-0ubuntu3
20231004.*
20231004.02-0ubuntu1
20231004.02-0ubuntu3
20240213.*
20240213.00-0ubuntu1
20240213.00-0ubuntu2
20240213.00-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "20240213.00-0ubuntu3.1",
            "binary_name": "google-guest-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent@20240320.00-0ubuntu1~24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240320.00-0ubuntu1~24.04.1

Affected versions

20230504.*
20230504.00-0ubuntu2
20230504.00-0ubuntu3
20240320.*
20240320.00-0ubuntu1~24.04.0

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "20240320.00-0ubuntu1~24.04.1",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
Ubuntu:25.10
golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf@1.36.5-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.36.5-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.36.5-1",
            "binary_name": "golang-google-protobuf-dev"
        },
        {
            "binary_version": "1.36.5-1",
            "binary_name": "protoc-gen-go"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
Ubuntu:Pro:16.04:LTS
google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent@20240524.03-0ubuntu2~16.04.0?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*
20210219.00-0ubuntu1~16.04.0
20230504.*
20230504.00-0ubuntu1~16.04.0
20240320.*
20240320.00-0ubuntu1~16.04.0
20240524.*
20240524.03-0ubuntu2~16.04.0

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20240524.03-0ubuntu2~16.04.0",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"
Ubuntu:Pro:18.04:LTS
google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent@20240926.03-0ubuntu1~18.04.0?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*
20210219.00-0ubuntu1~18.04.0
20210608.*
20210608.1-0ubuntu1~18.04.1
20210608.1-0ubuntu1~18.04.2
20220824.*
20220824.00-0ubuntu1~18.04.1
20230504.*
20230504.00-0ubuntu1~18.04.0
20240320.*
20240320.00-0ubuntu1~18.04.0
20240524.*
20240524.03-0ubuntu2~18.04.0
20240926.*
20240926.03-0ubuntu1~18.04.0

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "20240926.03-0ubuntu1~18.04.0",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"