Hanayoshi-8744 opened a new pull request, #51559:
URL: https://github.com/apache/arrow/pull/51559

   ### Rationale for this change
   
   The bundled Apache Thrift dependency (0.22.0) is affected by
   CVE-2026-55969, an integer overflow vulnerability in
   `TTransport::checkReadBytesAvailable()` that could bypass message
   size checks when reading maliciously crafted Thrift-encoded data.
   Arrow's Parquet module relies on Thrift's compact protocol to
   deserialize Parquet file metadata, so this is relevant to Arrow.
   
   ### What changes are included in this PR?
   
   - Bump the bundled Apache Thrift version from 0.22.0 to 0.24.0 in
     `cpp/thirdparty/versions.txt` (including the SHA256 checksum).
   - Remove the Clang-only `thrift-3187.patch` and its application logic
     in `ThirdpartyToolchain.cmake`. This patch pre-applied Thrift's
     upstream fix for THRIFT-3268 (a compiler warning), which has since
     been merged into Thrift itself and is already included in 0.24.0.
     Keeping the patch would make `git apply`/`patch` fail during the
     bundled build with Clang.
   
   ### Are these changes tested?
   
   - Verified that `thrift-0.24.0.tar.gz` downloads correctly and its
     SHA256 checksum matches the value published at
     downloads.apache.org.
   - Confirmed the CVE fix is present in Thrift 0.24.0 by diffing
     `TProtocol.h`, `TCompactProtocol.h`, `TBinaryProtocol.h`, and
     `TTransport.h` against 0.22.0.
   - Confirmed `thrift-3187.patch` no longer applies cleanly against
     0.24.0 sources (already fixed upstream), which is why it was
     removed rather than kept as a no-op.
   - Built Arrow C++ locally with `-DARROW_PARQUET=ON
     -DARROW_BUILD_TESTS=ON -DThrift_SOURCE=BUNDLED` and ran
     `parquet-internals-test`, `parquet-file-deserialize-test`,
     `parquet-schema-test`, `parquet-reader-test`, and
     `parquet-writer-test`. All tests passed.
   
   ### Are there any user-facing changes?
   
   No.
   
   * GitHub Issue: #51354
   
   ---
   
   Disclosure: this change was prepared with the assistance of an AI
   coding tool (Claude Code). I reviewed the diff, verified the CVE fix
   and checksum myself, and ran the test suite locally before opening
   this PR.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to