Impact
The flaw in Apache Thrift’s c_glib TZlibTransport causes the RPC layer to perform a full read after a premature stream end or to return an incorrect status code, exposing the system to uninitialized resource usage. This can result in corrupted data being returned to callers, unexpected application behavior, or a logic‑based denial of service if the transport repeatedly encounters incomplete reads.
Affected Systems
Apache Thrift components built against versions earlier than 0.25.0, particularly the c_glib binding utilizing TZlibTransport, are vulnerable. All deployments that use these bindings without the patch are affected.
Risk and Exploitability
With a CVSS score of 6.3 the vulnerability is considered medium severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, reducing the probability of already known exploitation. The attack vector is not explicitly described in the advisory; however, the flaw is reachable via networked Thrift calls that exercise the TZlibTransport endpoint, suggesting a remote or, at minimum, a local attack could trigger the premature read and corrupt the transport state.
OpenCVE Enrichment