{"id":"CVE-2025-47436","summary":"Apache ORC: Potential Heap Buffer Overflow during C++ LZO Decompression","details":"Heap-based Buffer Overflow vulnerability in Apache ORC.\n\nA vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption.\n\nThis issue affects Apache ORC C++ library: through 1.8.8, from 1.9.0 through 1.9.5, from 2.0.0 through 2.0.4, from 2.1.0 through 2.1.1.\n\nUsers are recommended to upgrade to version 1.8.9, 1.9.6, 2.0.5, and 2.1.2, which fix the issue.","modified":"2026-08-12T03:51:12.538593331Z","published":"2025-05-14T13:11:36.329Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47436.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"1.8.8"},{"introduced":"1.9.0"},{"last_affected":"1.9.5"},{"introduced":"2.0.0"},{"last_affected":"2.0.4"},{"introduced":"2.1.0"},{"last_affected":"2.1.1"}]},{"extracted_events":[{"fixed":"1.8.8"},{"introduced":"1.9.0"},{"fixed":"1.9.5"},{"introduced":"2.0.0"},{"fixed":"2.0.4"},{"introduced":"2.1.0"},{"fixed":"2.1.1"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/05/13/4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47436.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47436"},{"type":"ADVISORY","url":"https://orc.apache.org/security/CVE-2025-47436/"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/kd6tlv8fs5jybmsgxr4vrkdxyc866wrn"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/orc","events":[{"introduced":"0"},{"fixed":"78f3ed1d2a1adf2497a7d0f8fb866915b25f1e9e"},{"introduced":"9d434392e46252bf6ad2a6414527d2e619f858e6"},{"fixed":"c1323aa478fa1a273f2dd4746c3cd23868616ea4"},{"introduced":"46eb6ff46c25a3c8763f8661dc5525bbe6a26550"},{"fixed":"a5988e6a07ea0343aed7be6d5a568d76cf9db432"},{"introduced":"2cb13946b71140be08b54111ff36fc17da5f09af"},{"fixed":"e955e2bb5a0c3c9a0bb24a9039405ecea1878444"}],"database_specific":{"cpe":"cpe:2.3:a:apache:orc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.8.9"},{"introduced":"1.9.0"},{"fixed":"1.9.6"},{"introduced":"2.0.0"},{"fixed":"2.0.5"},{"introduced":"2.1.0"},{"fixed":"2.1.2"}],"source":"CPE_RANGE"}}],"versions":["v2.0.4-rc0","v2.0.4","rel/release-2.0.4","v2.1.1-rc0","v2.1.1","rel/release-2.1.1","v2.1.0-rc0","v2.1.0","rel/release-2.1.0","v2.0.3-rc0","v2.0.3","rel/release-2.0.3","v1.9.5-rc0","v1.9.5","rel/release-1.9.5","v1.8.8-rc0","v1.8.8","rel/release-1.8.8","v2.0.2-rc0","v2.0.2","rel/release-2.0.2","v1.9.4-rc0","v1.9.4","rel/release-1.9.4","v2.0.1-rc0","v2.0.1","rel/release-2.0.1","v1.8.7-rc0","v1.8.7","rel/release-1.8.7","v1.9.3-rc0","v1.9.3","rel/release-1.9.3","v2.0.0-rc0","v2.0.0","rel/release-2.0.0","v1.8.6-rc0","v1.8.6","rel/release-1.8.6","v1.9.2-rc0","v1.9.2","rel/release-1.9.2","v1.8.5-rc0","v1.8.5","rel/release-1.8.5","v1.9.1-rc0","v1.9.1","rel/release-1.9.1","v1.9.0-rc0","v1.9.0","rel/release-1.9.0","v1.8.4-rc0","v1.8.4","rel/release-1.8.4","v1.8.3-rc0","v1.8.3","rel/release-1.8.3","v1.8.2-rc0","v1.8.2","rel/release-1.8.2","v1.8.1-rc0","v1.8.1","rel/release-1.8.1","v1.8.0-rc0","v1.8.0","rel/release-1.8.0","rel/release-1.2.0","rel/release-1.1.0","rel/release-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47436.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/S:N/RE:M/U:Amber"}]}