Skip to content
Apache ArrowGHSA-8cw2-jv5c-c825

Missing Initialization of Resource in Apache Arrow

High7.5CVE-2019-12408 · Published May 24, 2022 · updated Oct 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
pyarrow
PyPI
>= 0.14.0, < 0.15.10.15.1
Details and references

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized memory being unintentionally shared if Arrow Arrays are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-909
Also known as
CVE-2019-12408, PYSEC-2019-195

More Apache Arrow advisories

All Apache Arrow
DateAdvisory
May 242022Missing Initialization of Resource in Apache Arrow
CVE-2019-12410High7.5fixed in 0.15.1
Nov 92023PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-47248Critical9.8fixed in 14.0.1
Nov 282024Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it
CVE-2024-52338Critical9.8fixed in 17.0.0
Feb 17Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-25087High7.0fixed in 23.0.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.