Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55971

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 8.4

Описание

A flaw was found in Apache Thrift C++ bindings. A remote, unauthenticated attacker can exploit a heap-based buffer overflow vulnerability without user interaction. This can lead to arbitrary code execution, allowing the attacker to gain full control over the affected system, compromise data, and cause a denial of service.

Отчет

This flaw affects the C++ implementation of Apache Thrift, specifically the ZLIB-enabled THeaderTransport (THeaderTransport::untransform()), which is reachable when a Thrift client or server negotiates the Header transport protocol with ZLIB compression enabled over a network connection. Red Hat ships the affected C++ package (thrift) in RHEL AI and in the Fedora/EPEL community distributions, and it is also consumed by AIPCC's PyArrow build pipeline (tracked separately as AIPCC-28667); upgrade to Apache Thrift 0.24.0 or later to remediate. Confirmed usage in RHEL AI 3.4's GPU bootc images and in the AIPCC PyArrow build pipeline is limited to PyArrow's Parquet metadata support, which serializes structs via Thrift's TCompactProtocol directly to an in-memory buffer and does not invoke THeaderTransport. As a result, this usage does not expose the vulnerable code path to network input; it would require local access to a maliciously crafted Parquet file instead. Other Red Hat components that reference Apache Thrift via the Go implementation (github.com/apache/thrift) or the Java Maven artifact (org.apache.thrift:libthrift) depend on independently implemented, separately maintained codebases; the Java bindings do not include the vulnerable ZLIB THeaderTransport code path (and CWE-122 heap corruption does not apply to JVM memory-managed arrays) and are therefore not affected.

Меры по смягчению последствий

No mitigation is available other than upgrading to Apache Thrift 0.24.0 or later, which contains the fix. AIPCC's PyArrow build pipeline is tracked separately for remediation under AIPCC-28667.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Not affected
Red Hat build of Apache Camel 4 for Quarkus 3libthriftNot affected
Red Hat Data Grid 8libthriftNot affected
Red Hat Enterprise Linux AI (RHEL AI) 3thriftAffected
Red Hat JBoss Enterprise Application Platform Expansion PacklibthriftNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-modelmesh-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-spark-operator-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch210-py312-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2507448thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
8 дней назад

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.8
nvd
8 дней назад

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CVSS3: 9.8
debian
8 дней назад

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...

CVSS3: 9.8
github
8 дней назад

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

8.4 High

CVSS3