{"id":"UBUNTU-CVE-2024-24786","details":"The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.","modified":"2026-07-23T20:36:57.067306816Z","published":"2024-03-05T23:15:00Z","related":["USN-6746-1","USN-6746-2"],"upstream":["CVE-2024-24786"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-24786"},{"type":"REPORT","url":"https://go-review.googlesource.com/c/protobuf/+/569356"},{"type":"REPORT","url":"https://go.dev/cl/569356"},{"type":"REPORT","url":"https://pkg.go.dev/vuln/GO-2024-2611"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-24786"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6746-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6746-2"}],"affected":[{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~16.04.0","20230504.00-0ubuntu1~16.04.0","20240320.00-0ubuntu1~16.04.0","20240524.03-0ubuntu2~16.04.0","20251028.00-0ubuntu2~16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~18.04.0","20210608.1-0ubuntu1~18.04.1","20210608.1-0ubuntu1~18.04.2","20220824.00-0ubuntu1~18.04.1","20230504.00-0ubuntu1~18.04.0","20240320.00-0ubuntu1~18.04.0","20240524.03-0ubuntu2~18.04.0","20240926.03-0ubuntu1~18.04.0","20251028.00-0ubuntu2~18.04.0"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~18.04.0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20210219.00-0ubuntu1~20.04.0","20210608.1-0ubuntu1~20.04.0","20210608.1-0ubuntu1~20.04.1","20220824.00-0ubuntu1~20.04.1","20230504.00-0ubuntu1~20.04.0","20240320.00-0ubuntu1~20.04.0","20240320.00-0ubuntu1~20.04.1","20240524.03-0ubuntu2~20.04.0","20240926.03-0ubuntu1~20.04.0","20250115.01-0ubuntu1~20.04.0","20251028.00-0ubuntu2~20.04.0"],"ecosystem_specific":{"binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20251028.00-0ubuntu2~20.04.0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"golang-google-protobuf","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-google-protobuf?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.25.0+git20201208.160c747-1","1.27.1-1","1.27.1-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.27.1-1ubuntu0.1","binary_name":"golang-google-protobuf-dev"},{"binary_name":"protoc-gen-go","binary_version":"1.27.1-1ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20231004.02-0ubuntu1~22.04.4"}]}],"versions":["20210629.00-0ubuntu1","20210629.00-0ubuntu2","20220104.00-0ubuntu1","20220104.00-0ubuntu2","20220622.00-0ubuntu2~22.04.0","20220622.00-0ubuntu2~22.04.1","20230426.00-0ubuntu2~22.04.0","20231004.02-0ubuntu1~22.04.1","20231004.02-0ubuntu1~22.04.2","20231004.02-0ubuntu1~22.04.3"],"ecosystem_specific":{"binaries":[{"binary_name":"google-guest-agent","binary_version":"20231004.02-0ubuntu1~22.04.4"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20230504.00-0ubuntu1~22.04.1"}]}],"versions":["20210608.1-0ubuntu1","20210608.1-0ubuntu2","20210608.1-0ubuntu3","20220824.00-0ubuntu1~22.04.1","20220824.00-0ubuntu1~22.04.2","20230504.00-0ubuntu1~22.04.0"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20230504.00-0ubuntu1~22.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"golang-google-protobuf","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-google-protobuf?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.28.1-3build1","1.31.0-1","1.32.0-1","1.32.0-1ubuntu0.1","1.32.0-1ubuntu0.2","1.32.0-1ubuntu0.3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-google-protobuf-dev","binary_version":"1.32.0-1ubuntu0.3"},{"binary_name":"protoc-gen-go","binary_version":"1.32.0-1ubuntu0.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-guest-agent","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/google-guest-agent?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20240213.00-0ubuntu3.1"}]}],"versions":["20230426.00-0ubuntu3","20231004.02-0ubuntu1","20231004.02-0ubuntu3","20240213.00-0ubuntu1","20240213.00-0ubuntu2","20240213.00-0ubuntu3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"google-guest-agent","binary_version":"20240213.00-0ubuntu3.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"google-osconfig-agent","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20240320.00-0ubuntu1~24.04.1"}]}],"versions":["20230504.00-0ubuntu2","20230504.00-0ubuntu3","20240320.00-0ubuntu1~24.04.0"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"google-osconfig-agent","binary_version":"20240320.00-0ubuntu1~24.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"golang-google-protobuf","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/golang-google-protobuf?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.36.5-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-google-protobuf-dev","binary_version":"1.36.5-1"},{"binary_name":"protoc-gen-go","binary_version":"1.36.5-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}},{"package":{"name":"golang-google-protobuf","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-google-protobuf?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.36.5-1","1.36.7-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-google-protobuf-dev","binary_version":"1.36.7-1"},{"binary_version":"1.36.7-1","binary_name":"protoc-gen-go"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-24786.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}