Hanayoshi-8744 opened a new pull request, #51559:
URL: https://github.com/apache/arrow/pull/51559
### Rationale for this change
The bundled Apache Thrift dependency (0.22.0) is affected by
CVE-2026-55969, an integer overflow vulnerability in
`TTransport::checkReadBytesAvailable()` that could bypass message
size checks when reading maliciously crafted Thrift-encoded data.
Arrow's Parquet module relies on Thrift's compact protocol to
deserialize Parquet file metadata, so this is relevant to Arrow.
### What changes are included in this PR?
- Bump the bundled Apache Thrift version from 0.22.0 to 0.24.0 in
`cpp/thirdparty/versions.txt` (including the SHA256 checksum).
- Remove the Clang-only `thrift-3187.patch` and its application logic
in `ThirdpartyToolchain.cmake`. This patch pre-applied Thrift's
upstream fix for THRIFT-3268 (a compiler warning), which has since
been merged into Thrift itself and is already included in 0.24.0.
Keeping the patch would make `git apply`/`patch` fail during the
bundled build with Clang.
### Are these changes tested?
- Verified that `thrift-0.24.0.tar.gz` downloads correctly and its
SHA256 checksum matches the value published at
downloads.apache.org.
- Confirmed the CVE fix is present in Thrift 0.24.0 by diffing
`TProtocol.h`, `TCompactProtocol.h`, `TBinaryProtocol.h`, and
`TTransport.h` against 0.22.0.
- Confirmed `thrift-3187.patch` no longer applies cleanly against
0.24.0 sources (already fixed upstream), which is why it was
removed rather than kept as a no-op.
- Built Arrow C++ locally with `-DARROW_PARQUET=ON
-DARROW_BUILD_TESTS=ON -DThrift_SOURCE=BUNDLED` and ran
`parquet-internals-test`, `parquet-file-deserialize-test`,
`parquet-schema-test`, `parquet-reader-test`, and
`parquet-writer-test`. All tests passed.
### Are there any user-facing changes?
No.
* GitHub Issue: #51354
---
Disclosure: this change was prepared with the assistance of an AI
coding tool (Claude Code). I reviewed the diff, verified the CVE fix
and checksum myself, and ran the test suite locally before opening
this PR.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]