Skip to content
Apache ArrowGHSA-cjw4-2w9r-r8mv

Missing Initialization of Resource in Apache Arrow

High7.5CVE-2019-12410 · Published May 24, 2022 · updated Oct 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
pyarrow
PyPI
>= 0.12.0, < 0.15.10.15.1
Details and references

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-909
Also known as
CVE-2019-12410, PYSEC-2019-196

More Apache Arrow advisories

All Apache Arrow
DateAdvisory
May 242022Missing Initialization of Resource in Apache Arrow
CVE-2019-12408High7.5fixed in 0.15.1
Nov 92023PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-47248Critical9.8fixed in 14.0.1
Nov 282024Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it
CVE-2024-52338Critical9.8fixed in 17.0.0
Feb 17Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-25087High7.0fixed in 23.0.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.