[
https://issues.apache.org/jira/browse/THRIFT-6093?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer resolved THRIFT-6093.
--------------------------------
Assignee: Jens Geyer
Resolution: Fixed
> Read the zlib transform result directly in THeaderTransport untransform
> -----------------------------------------------------------------------
>
> Key: THRIFT-6093
> URL: https://issues.apache.org/jira/browse/THRIFT-6093
> Project: Thrift
> Issue Type: Bug
> Components: C++ - Library
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Major
> Fix For: 0.24.0
>
>
> THeaderTransport::untransform() inflated the ZLIB-compressed section into a
> transform buffer sized for the decompressed output, then copied the result
> back into the (smaller) frame receive buffer at its original location -- a
> copy that can write past the end of that buffer when the decompressed data is
> larger than the space available there.
> Fixed by swapping the transform buffer in as the receive buffer directly
> (rBuf_.swap(tBuf_)) instead of copying the decompressed result back into the
> smaller buffer.
> *Affects:* C++; the vulnerable copy-back pattern is also present in 0.23.0
> *Fixed by:* commit 06e768713; fixed in 0.24.0
> *CWE-122:* Heap-based Buffer Overflow
> *CVSS 4.0:* 9.3 Critical
> ({{CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N}})
> *Reported by:* Ghaith Abdulreda, via [email protected]
> *CVE:* CVE-2026-55971
--
This message was sent by Atlassian Jira
(v8.20.10#820010)