Impact
Apache Thrift’s C++ implementation of THeaderProtocol contains a stack‑based buffer overflow in the writeVarint32() function. The bug is triggered when a negative protocol identifier is processed, causing an incorrect bitwise shift of an integer that overflows a 32‑bit buffer. The overflow corrupts stack memory and can enable an attacker to inject and execute arbitrary code. The flaw is classified under CWE‑121 (Stack Smashing), CWE‑1335 (Incorrect Bitwise Shift), CWE‑787 (Out‑of‑Bounds Write), and CWE‑835 (Infinite Loop).
Affected Systems
All releases of Apache Thrift prior to version 0.25.0 are affected. The library is widely used in client and server applications that expose Thrift interfaces over a network.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, and the issue has not been listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw can be exploited through a network‑bound Thrift client: a malicious actor who can send a malformed request with a negative protocol id can trigger the overflow and potentially achieve arbitrary code execution on the host running the Thrift service. No authentication or privilege requirement is mentioned, so the vector is likely remote, the path is network, and the scope is the service process.
OpenCVE Enrichment