GHSA-cjw4-2w9r-r8mv

Source
https://github.com/advisories/GHSA-cjw4-2w9r-r8mv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cjw4-2w9r-r8mv/GHSA-cjw4-2w9r-r8mv.json
Aliases
Published
2022-05-24T17:00:40Z
Modified
2023-11-08T04:01:04.600457Z
Details

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

References

Affected packages

PyPI / pyarrow

Package

Name
pyarrow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.0
Fixed
0.15.1

Affected versions

0.*

0.12.0
0.12.1
0.13.0
0.14.0
0.14.1
0.15.0

RubyGems / red-arrow

Package

Name
red-arrow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.0
Fixed
0.15.1

Affected versions

0.*

0.12.0
0.13.0
0.14.0
0.14.1
0.15.0