OSV-2025-852
Dashboard / Vulnerabilities / OSV-2025-852
OSV-2025-852
Published: 23 Oct 2025Last Modified: 24 Oct 2025
Summary: Heap-buffer-overflow in std::__1::pair<int, arrow::util::RleBitPackedParser::ControlFlow> arrow::util::R
Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=454097865 ``` Crash type: Heap-buffer-overflow READ 1 Crash state: std::__1::pair<int, arrow::util::RleBitPackedParser::ControlFlow> arrow::util::R arrow::util::RleBitPackedDecoder<int>::GetBatch auto parquet::DictByteArrayDecoderImpl::DecodeArrowDense ```
Affected packages
Package
Name: arrow
Purl: pkg:generic/arrow
Affected ranges
Type: GIT
Events:
Introduced- 64f2055ffb68e5077420f4253e76d78952438cab
Affected versions
apache-arrow-22.0.0-rc0
apache-arrow-22.0.0-rc1
apache-arrow-22.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
