Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-48431

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

A flaw was found in Apache Thrift c_glib language bindings. A remote attacker could send specially crafted requests to a c_glib-based Thrift server, leading to a mismatched memory management routines vulnerability. This could cause the server to crash with a "free(): invalid pointer" error, resulting in a Denial of Service (DoS).

Отчет

This is an Important denial of service vulnerability affecting Apache Thrift c_glib language bindings. Remote attackers can exploit this flaw by sending specially crafted requests to a c_glib-based Thrift server, leading to a server crash and service disruption. This impact is considered Important due to the potential for unauthenticated remote denial of service in Red Hat products that deploy and expose such Thrift servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-212Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/grafana-acm-213Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat Ceph Storage 5rhceph/snmp-notifier-rhel8Out of support scope
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Out of support scope
Red Hat Ceph Storage 6rhceph/snmp-notifier-rhel9Out of support scope
Red Hat Ceph Storage 8rhceph/grafana-rhel9Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-763
https://bugzilla.redhat.com/show_bug.cgi?id=2463410Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests

EPSS

Процентиль: 62%
0.01079
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

CVSS3: 7.5
nvd
4 месяца назад

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

msrc
4 месяца назад

Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

CVSS3: 7.5
debian
4 месяца назад

Mismatched Memory Management Routines vulnerability in Apache Thrift c ...

CVSS3: 7.5
github
4 месяца назад

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

EPSS

Процентиль: 62%
0.01079
Низкий

7.5 High

CVSS3