AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-53605.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.9No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSMicrosoft vendor recordModified Oct 06, 2026

Disclosure summary

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Source-reported weakness categories

CWE-674

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Microsoft Security Updates (CVRF) · 2025-Jul

Open original source · Updated Oct 06, 2026

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.

Microsoft maximum product score: 5.9

VendorProduct / associationVersion / bounds
Microsoft update guideazl3 kata-containers 3.18.0.kata0-3 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kata-containers-cc 3.15.0.aks0-4 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 rust 1.86.0-4 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers 3.2.0.azl2-6 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers-cc 3.2.0.azl2-7 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers-cc 3.2.0.azl2-8 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guideazl3 kata-containers-cc 3.15.0.aks0-5 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guidecbl2 rust 1.72.0-10 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 rust 1.72.0-11 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guideazl3 kata-containers-cc 3.15.0.aks0-6 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 rust 1.75.0-17 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guidecbl2 rust 1.72.0-10 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers 3.2.0.azl2-7 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers 3.2.0.azl2-7 on CBL-Mariner 2.0 (MSRC status code 3)
Microsoft update guidecbl2 kata-containers-cc 3.2.0.azl2-8 on CBL-Mariner 2.0 (MSRC status code 3)

Vendor remediation references

  • CBL-Mariner Releases · build 3.19.1.kata2-1 · product IDs 20337-17084
  • Vendor guidance · product IDs 20337-17084
  • CBL-Mariner Releases · build 1.86.0-4 · product IDs 20141-17084
  • Vendor guidance · product IDs 20141-17084
  • CBL-Mariner Releases · build 1.72.0-11 · product IDs 17183-17086, 20605-17086
  • Vendor guidance · product IDs 17183-17086, 20605-17086
  • CBL-Mariner Releases · build 1.75.0-17 · product IDs 20329-17084
  • Vendor guidance · product IDs 20329-17084
  • Release Notes · product IDs 20393-21692, 20394-21692
  • Vendor guidance · product IDs 20393-21692, 20394-21692

Original records & references

PUBLISHED 2025-09-03T23:26:57-04:00
MODIFIED 2026-10-06T21:48:58-04:00
INGESTED 2026-10-08T12:45:47-04:00