OSV-2025-788

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/arrow/OSV-2025-788.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-788
Published
2025-09-28T00:00:36Z
Modified
2025-10-10T14:35:28Z
Summary
Heap-buffer-overflow in int arrow::bit_util::BitReader::GetBatch<int>
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=447480433

Crash type: Heap-buffer-overflow READ 8
Crash state:
int arrow::bit_util::BitReader::GetBatch<int>
auto arrow::util::RleBitPackedDecoder<int>::GetBatch
std::__1::pair<int, arrow::util::RleBitPackedParser::ControlFlow> arrow::util::R
References

Affected packages

OSS-Fuzz / arrow

Package

Name
arrow
Purl
pkg:generic/arrow

Affected ranges

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

introduced_range
"e68236ae36385127b851ca129ed0cbc1078cae48:235032ad245030c6364a9c8ec02066c0aa0bb18d"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/arrow/OSV-2025-788.yaml"