Impact
A heap‑based buffer overflow arises when the C++ THttpTransport component in Apache Thrift expands its line buffer without constraining the size of incoming data. The absence of size limits coupled with integer overflow and wrap‑around vulnerabilities allows an attacker to supply excessive input that corrupts memory. If an attacker succeeds, they could crash the Thrift service or potentially execute arbitrary code, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Apache Software Foundation’s Apache Thrift is affected in all releases prior to version 0.25.0. Any deployment running a version older than 0.25.0 that utilizes the C++ THttpTransport transport layer is susceptible to the described flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.2, denoting critical severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but the high CVSS score suggests that exploitation would enable an attacker to gain remote execution privileges. The likely attack vector is remote, as the thickness of data is controlled via HTTP requests to the Thrift service. Exploitation requires network access to the Thrift service and relies on the ability to send unbounded or malformed input that triggers the integer overflow and subsequent buffer overflow.
OpenCVE Enrichment