Impact
Apache Thrift’s C++ THeaderTransport contains an integer underflow that can trigger an out‑of‑bounds write. An attacker who can send data to the transport can exploit the underflow by causing the internal size counters to wrap, resulting in a buffer overflow that writes beyond the intended boundary. The overflow can corrupt internal state or overwrite executable code, potentially terminating the 32‑bit Thrift server process. The impact is that the affected service becomes unavailable, impacting availability through denial of service.
Affected Systems
The issue affects Apache Thrift C++ prior to version 0.25.0 when running on 32‑bit platforms. Any deployment that uses the THeaderTransport interface is susceptible. Users should verify that their Thrift version is 0.25.0 or newer, or that they are running a 64‑bit build, which is not listed as affected.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is publicly known and listed as not in CISA KEV, but it can be reached over the network by an unauthenticated remote peer. Because the attack does not require authentication, an external adversary can craft a malformed header that causes the integer underflow and leads to a crash of the Thrift service, thereby disrupting availability of the application or any dependent services.
OpenCVE Enrichment