Описание
A flaw was found in Apache Thrift C++ bindings. A remote, unauthenticated attacker can exploit a heap-based buffer overflow vulnerability without user interaction. This can lead to arbitrary code execution, allowing the attacker to gain full control over the affected system, compromise data, and cause a denial of service.
Отчет
This flaw affects the C++ implementation of Apache Thrift, specifically the ZLIB-enabled THeaderTransport (THeaderTransport::untransform()), which is reachable when a Thrift client or server negotiates the Header transport protocol with ZLIB compression enabled over a network connection. Red Hat ships the affected C++ package (thrift) in RHEL AI and in the Fedora/EPEL community distributions, and it is also consumed by AIPCC's PyArrow build pipeline (tracked separately as AIPCC-28667); upgrade to Apache Thrift 0.24.0 or later to remediate. Confirmed usage in RHEL AI 3.4's GPU bootc images and in the AIPCC PyArrow build pipeline is limited to PyArrow's Parquet metadata support, which serializes structs via Thrift's TCompactProtocol directly to an in-memory buffer and does not invoke THeaderTransport. As a result, this usage does not expose the vulnerable code path to network input; it would require local access to a maliciously crafted Parquet file instead. Other Red Hat components that reference Apache Thrift via the Go implementation (github.com/apache/thrift) or the Java Maven artifact (org.apache.thrift:libthrift) depend on independently implemented, separately maintained codebases; the Java bindings do not include the vulnerable ZLIB THeaderTransport code path (and CWE-122 heap corruption does not apply to JVM memory-managed arrays) and are therefore not affected.
Меры по смягчению последствий
No mitigation is available other than upgrading to Apache Thrift 0.24.0 or later, which contains the fix. AIPCC's PyArrow build pipeline is tracked separately for remediation under AIPCC-28667.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Not affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | libthrift | Not affected | ||
| Red Hat Data Grid 8 | libthrift | Not affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | libthrift | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-modelmesh-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
8.4 High
CVSS3
Связанные уязвимости
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
8.4 High
CVSS3