Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43868

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

A flaw was found in Apache Thrift. This vulnerability involves a Memory Allocation with Excessive Size Value, which could allow an attacker to trigger resource exhaustion. By providing an overly large size value during memory allocation, an attacker can cause the affected system to become unresponsive, leading to a Denial of Service (DoS).

Отчет

This is an Important denial of service flaw in Apache Thrift, allowing an unauthenticated remote attacker to exhaust system resources. By sending specially crafted requests with excessive size values, an attacker can cause memory allocation failures, leading to system unresponsiveness. This poses a significant risk to the availability of services utilizing vulnerable Apache Thrift implementations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2466670Apache Thrift: Apache Thrift: Denial of Service via excessive memory allocation

EPSS

Процентиль: 50%
0.00706
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

msrc
3 месяца назад

Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern

CVSS3: 5.3
debian
3 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache Th ...

CVSS3: 5.3
github
3 месяца назад

Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability

EPSS

Процентиль: 50%
0.00706
Низкий

7.5 High

CVSS3