Source: thrift
Version: 0.19.0-4
Severity: grave
Tags: patch security
X-Debbugs-Cc: [email protected]

Hello Apache Thrift maintainers,

I am requesting a backport of CVE-2026-55971 to Trixie. An unauthenticated
`THeaderTransport` frame can request ZLIB decompression and cause
`untransform()` to copy the expanded data beyond its receive-buffer allocation.

Running `./run-poc.sh` against Trixie's package produces an AddressSanitizer
heap-buffer-overflow. The rebuilt library remains running and processes the
expanded frame correctly.

Upstream fix:

https://github.com/apache/thrift/commit/db4a473f3a984eee27273256fe737be5dd175595

The attached patch applies cleanly and the C++ libraries rebuild successfully.
Could it be included in a Trixie security update?

AI tools assisted this research and draft. The patch and PoC were manually
validated against Trixie.

Regards,
Artem Dinaburg
Trail of Bits

Attachment: fix.patch
Description: Binary data

Attachment: poc.tar.gz
Description: GNU Zip compressed data

Reply via email to