CVE-2025-48431
published 2026-04-28CVE-2025-48431: Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.08%
61.4th percentile
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| cryostat | cryostat-storage-rhel9 | — | — |
| grafana | grafana | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | cnf-tests-rhel8 | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| redhat-user-workloads | cnf-tests-4-15 | — | — |
| redhat-user-workloads | grafana-acm-212 | — | — |
| redhat-user-workloads | grafana-acm-213 | — | — |
| redhat-user-workloads | ztp-site-generate-4-15 | — | — |
| redhat-user-workloads | ztp-site-generate-4-16 | — | — |
| rhacm2 | acm-grafana-rhel9_1780677003 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhceph | alloy-rhel10 | — | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | grafana-rhel9 | — | — |
| rhceph | rhceph-6-dashboard-rhel9 | — | — |
| rhceph | snmp-notifier-rhel10 | — | — |
| rhceph | snmp-notifier-rhel8 | — | — |
| rhceph | snmp-notifier-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Thrift up to 0.22.0 glibc denial of service
vuldb·2026-04-28
CVE-2025-48431 [LOW] Apache Thrift up to 0.22.0 glibc denial of service
A vulnerability categorized as problematic has been discovered in Apache Thrift up to 0.22.0. This affects an unknown function of the component glibc. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2025-48431. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-ppv5-592p-g5q4: Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings
ghsa_unreviewed·2026-04-28
CVE-2025-48431 [HIGH] CWE-762 GHSA-ppv5-592p-g5q4: Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
Red Hat
Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
vendor_redhat·2026-04-28·CVSS 7.5
CVE-2025-48431 [HIGH] CWE-763 Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
A flaw was found in Apache Thrift c_glib language bindings. A remote attacker could send specially crafted requests to a c_glib-based Thrift server, leading to a mismatched memory management routines vulnerability. This could cause the server to crash with a "free(): invalid pointer" error, resulting in a Denial of Service (DoS).
Package:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-48431 golang-github-apache-thrift: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
bugzilla·2026-06-08·CVSS 7.5
CVE-2025-48431 [HIGH] CVE-2025-48431 golang-github-apache-thrift: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
CVE-2025-48431 golang-github-apache-thrift: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-48431 migrate: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
bugzilla·2026-06-08·CVSS 7.5
CVE-2025-48431 [HIGH] CVE-2025-48431 migrate: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
CVE-2025-48431 migrate: Apache Thrift c_glib: Denial of Service via specially crafted requests [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-48431 Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
bugzilla·2026-04-28·CVSS 7.5
CVE-2025-48431 [HIGH] CVE-2025-48431 Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
CVE-2025-48431 Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwqlhttp://www.openwall.com/lists/oss-security/2026/04/28/8https://access.redhat.com/errata/RHSA-2026:24539https://access.redhat.com/errata/RHSA-2026:25273https://access.redhat.com/errata/RHSA-2026:27126https://access.redhat.com/errata/RHSA-2026:28010https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/security/cve/CVE-2025-48431https://bugzilla.redhat.com/show_bug.cgi?id=2463410https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48431.json
2026-04-28
Published