Impact
This vulnerability is an integer overflow or wraparound in the Go implementation of Apache Thrift’s TFramedTransport. The flaw can cause the transport to incorrectly calculate frame lengths, potentially leading to memory corruption or application crashes. As a result, a malicious actor could disrupt service availability or achieve stronger attacks if additional vulnerabilities are present.
Affected Systems
The issue affects the Apache Thrift project distributed by the Apache Software Foundation, specifically all versions prior to 0.23.0 for the Go language implementation.
Risk and Exploitability
The exploitability of this flaw is not publicly documented and no exploit statistics are available. The EPSS score is less than 1%, and the CVSS score is 7.5, indicating a high severity. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves remote clients sending crafted frames to a Thrift server, but this is inferred rather than explicitly stated in the advisory.
OpenCVE Enrichment