CVE-2025-47436
Last modified
CVE-2025-47436 is a medium-severity vulnerability rated 6/10 on the CVSS scale. Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption. This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1. Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption. This issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1. Users are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:M/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Orc | < 1.8.9 |
| Apache | Orc | >= 1.9.0, < 1.9.6 |
| Apache | Orc | >= 2.0.0, < 2.0.5 |
| Apache | Orc | >= 2.1.0, < 2.1.2 |
References
- https://lists.apache.org/thread/kd6tlv8fs5jybmsgxr4vrkdxyc866wrnMailing List, Vendor Advisory
- https://orc.apache.org/security/CVE-2025-47436/Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/05/13/4Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-47436?
How severe is CVE-2025-47436?
How do I fix CVE-2025-47436?
Are you affected by CVE-2025-47436?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
