eap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption. This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1. Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/kd6tlv8fs5jybmsgxr4vrkdxyc866wrn | Mailing List Vendor Advisory |
| https://orc.apache.org/security/CVE-2025-47436/ | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/05/13/4 | Mailing List Third Party Advisory |
Configuration 1 (hide)
|
14 Jul 2025, 14:55
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://lists.apache.org/thread/kd6tlv8fs5jybmsgxr4vrkdxyc866wrn - Mailing List, Vendor Advisory | |
| References | () https://orc.apache.org/security/CVE-2025-47436/ - Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/05/13/4 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:* | |
| First Time |
Apache
Apache orc |
16 May 2025, 14:43
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
14 May 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-05-14 14:15
Updated : 2025-07-14 14:55
NVD link : CVE-2025-47436
Mitre link : CVE-2025-47436
CVE.ORG link : CVE-2025-47436
JSON object : View
Heap-based Buffer Overflow