UBUNTU-CVE-2024-24786

Source
https://ubuntu.com/security/CVE-2024-24786
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-24786
Related
Published
2024-03-05T23:15:00Z
Modified
2024-10-15T14:12:53Z
Summary
[none]
Details

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

References

Affected packages

Ubuntu:Pro:16.04:LTS / google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20201217.*

20201217.02-0ubuntu1~16.04.0

20230426.*

20230426.00-0ubuntu2~16.04.3

20231004.*

20231004.02-0ubuntu1~16.04.1
20231004.02-0ubuntu1~16.04.2

20240716.*

20240716.00-0ubuntu1~16.04.0

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*

20210219.00-0ubuntu1~16.04.0

20230504.*

20230504.00-0ubuntu1~16.04.0

20240320.*

20240320.00-0ubuntu1~16.04.0

20240524.*

20240524.03-0ubuntu2~16.04.0

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20201217.*

20201217.02-0ubuntu1~18.04.0

20210414.*

20210414.00-0ubuntu1~18.04.0

20210629.*

20210629.00-0ubuntu1~18.04.1

20220622.*

20220622.00-0ubuntu2~18.04.0
20220622.00-0ubuntu2~18.04.1

20230426.*

20230426.00-0ubuntu2~18.04.0

20231004.*

20231004.02-0ubuntu1~18.04.2
20231004.02-0ubuntu1~18.04.3

20240716.*

20240716.00-0ubuntu1~18.04.0

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*

20210219.00-0ubuntu1~18.04.0

20210608.*

20210608.1-0ubuntu1~18.04.1
20210608.1-0ubuntu1~18.04.2

20220824.*

20220824.00-0ubuntu1~18.04.1

20230504.*

20230504.00-0ubuntu1~18.04.0

20240320.*

20240320.00-0ubuntu1~18.04.0

20240524.*

20240524.03-0ubuntu2~18.04.0

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20210219.*

20210219.00-0ubuntu1~20.04.0

20210608.*

20210608.1-0ubuntu1~20.04.0
20210608.1-0ubuntu1~20.04.1

20220824.*

20220824.00-0ubuntu1~20.04.1

20230504.*

20230504.00-0ubuntu1~20.04.0

20240320.*

20240320.00-0ubuntu1~20.04.0
20240320.00-0ubuntu1~20.04.1

20240524.*

20240524.03-0ubuntu2~20.04.0

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.25.0+git20201208.160c747-1
1.27.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20231004.02-0ubuntu1~22.04.4

Affected versions

20210629.*

20210629.00-0ubuntu1
20210629.00-0ubuntu2

20220104.*

20220104.00-0ubuntu1
20220104.00-0ubuntu2

20220622.*

20220622.00-0ubuntu2~22.04.0
20220622.00-0ubuntu2~22.04.1

20230426.*

20230426.00-0ubuntu2~22.04.0

20231004.*

20231004.02-0ubuntu1~22.04.1
20231004.02-0ubuntu1~22.04.2
20231004.02-0ubuntu1~22.04.3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20231004.02-0ubuntu1~22.04.4",
            "binary_name": "google-guest-agent"
        }
    ]
}

Ubuntu:22.04:LTS / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20230504.00-0ubuntu1~22.04.1

Affected versions

20210608.*

20210608.1-0ubuntu1
20210608.1-0ubuntu2
20210608.1-0ubuntu3

20220824.*

20220824.00-0ubuntu1~22.04.1
20220824.00-0ubuntu1~22.04.2

20230504.*

20230504.00-0ubuntu1~22.04.0

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20230504.00-0ubuntu1~22.04.1",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Ubuntu:24.10 / golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.32.0-1
1.33.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240213.00-0ubuntu4

Affected versions

20240213.*

20240213.00-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20240213.00-0ubuntu4",
            "binary_name": "google-guest-agent"
        }
    ]
}

Ubuntu:24.10 / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240320.00-0ubuntu2

Affected versions

20230504.*

20230504.00-0ubuntu3

20240320.*

20240320.00-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20240320.00-0ubuntu2",
            "binary_name": "google-osconfig-agent"
        }
    ]
}

Ubuntu:24.04:LTS / golang-google-protobuf

Package

Name
golang-google-protobuf
Purl
pkg:deb/ubuntu/golang-google-protobuf?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.28.1-3build1
1.31.0-1
1.32.0-1
1.32.0-1ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:deb/ubuntu/google-guest-agent?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240213.00-0ubuntu3.1

Affected versions

20230426.*

20230426.00-0ubuntu3

20231004.*

20231004.02-0ubuntu1
20231004.02-0ubuntu3

20240213.*

20240213.00-0ubuntu1
20240213.00-0ubuntu2
20240213.00-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20240213.00-0ubuntu3.1",
            "binary_name": "google-guest-agent"
        }
    ]
}

Ubuntu:24.04:LTS / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:deb/ubuntu/google-osconfig-agent?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20240320.00-0ubuntu1~24.04.1

Affected versions

20230504.*

20230504.00-0ubuntu2
20230504.00-0ubuntu3

20240320.*

20240320.00-0ubuntu1~24.04.0

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20240320.00-0ubuntu1~24.04.1",
            "binary_name": "google-osconfig-agent"
        }
    ]
}