[
https://issues.apache.org/jira/browse/THRIFT-6091?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer resolved THRIFT-6091.
--------------------------------
Assignee: Jens Geyer
Resolution: Fixed
> Widen container-size precheck to 64-bit in C++, C/GLib, Go, netstd, Delphi,
> and Haxe protocols
> ----------------------------------------------------------------------------------------------
>
> Key: THRIFT-6091
> URL: https://issues.apache.org/jira/browse/THRIFT-6091
> Project: Thrift
> Issue Type: Bug
> Components: C glib - Library, C++ - Library, Delphi - Library, Go -
> Library, Haxe - Library, netstd - Library
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Major
> Fix For: 0.24.0
>
>
> The container-size precheck that multiplies an on-wire element count by the
> minimum element size, used to reject oversized list/set/map allocations
> before they are attempted, performed that multiply in 32-bit arithmetic. A
> crafted count near the top of the valid range could overflow the multiply and
> wrap to a small value, letting an oversized allocation slip past the check.
> Fixed by widening the precheck multiply to 64-bit across the affected
> implementations:
> * C++ / C-GLib: PR #3590 (commit 983c813c9)
> * Go: commits ed643a86d and 137d693e2 (binary/compact and JSON paths)
> * netstd, Delphi, Haxe: commit 80ed45a71
> *Affects:* C++, C/GLib, and Go confirmed present in 0.23.0; fixed in 0.24.0
> *Fixed by:* see commits above; the C++/C-GLib fix (PR #3590) was already
> public in master prior to this report
> *CWE-190:* Integer Overflow or Wraparound
> *CVSS 4.0:* 8.7 High
> ({{CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N}})
> *Reported by:* Ghaith Abdulreda, via [email protected]; fix contributed by
> Javid Khan (PR #3590, PR #3604) and Jens Geyer (netstd/Delphi/Haxe, Go JSON
> path)
> *CVE:* CVE-2026-55969
--
This message was sent by Atlassian Jira
(v8.20.10#820010)