OSV-2025-852

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/arrow/OSV-2025-852.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-852
Published
2025-10-23T00:13:16.148747Z
Modified
2025-10-24T14:23:38.843951Z
Summary
Heap-buffer-overflow in std::__1::pair<int, arrow::util::RleBitPackedParser::ControlFlow> arrow::util::R
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=454097865

Crash type: Heap-buffer-overflow READ 1
Crash state:
std::__1::pair&lt;int, arrow::util::RleBitPackedParser::ControlFlow> arrow::util::R
arrow::util::RleBitPackedDecoder<int>::GetBatch
auto parquet::DictByteArrayDecoderImpl::DecodeArrowDense
References

Affected packages

OSS-Fuzz / arrow

Package

Name
arrow
Purl
pkg:generic/arrow

Affected ranges

Affected versions

apache-arrow-22.*

apache-arrow-22.0.0
apache-arrow-22.0.0-rc0
apache-arrow-22.0.0-rc1

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range

"f268c43ccd86ac57336e3a49a75261d63147ea37:52704cbb4e6c0275b36e5ffc6a395361be05c262"

introduced_range

"e68236ae36385127b851ca129ed0cbc1078cae48:235032ad245030c6364a9c8ec02066c0aa0bb18d"