pitrou opened a new pull request, #49060:
URL: https://github.com/apache/arrow/pull/49060

   ### Rationale for this change
   
   Fix two issues found by OSS-Fuzz in the IPC reader:
   
   * a controlled abort on invalid IPC metadata: 
https://oss-fuzz.com/testcase-detail/5301064831401984
   * a nullptr dereference on invalid IPC metadata: 
https://oss-fuzz.com/testcase-detail/5091511766417408
   
   None of these two issues is a security issue.
   
   ### Are these changes tested?
   
   Yes, by new unit tests and new fuzz regression files.
   
   ### Are there any user-facing changes?
   
   No.
   
   **This PR contains a "Critical Fix".** (If the changes fix either (a) a 
security vulnerability, (b) a bug that caused incorrect or invalid data to be 
produced, or (c) a bug that causes a crash (even when the API contract is 
upheld), please provide explanation. If not, you can remove this.)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to