CVE-2025-47436

Severity CVSS v4.0:
MEDIUM
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
14/05/2025
Last modified:
14/07/2025

Description

Heap-based Buffer Overflow vulnerability in Apache ORC.<br /> <br /> A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption.<br /> <br /> This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1.<br /> <br /> Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:* 1.8.9 (excluding)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:* 1.9.0 (including) 1.9.6 (excluding)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.5 (excluding)
cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.2 (excluding)