Apache Orc vulnerabilities
3 known vulnerabilities affecting apache/orc.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-47436P3CRITICALCVSS 9.8fixed in 1.8.9≥ 1.9.0, < 1.9.6+2 more2025-05-14
CVE-2025-47436 [CRITICAL] CWE-122 CVE-2025-47436: Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the
Heap-based Buffer Overflow vulnerability in Apache ORC.
A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to copy 295 bytes into it. It causes memory corruption.
This issue affects Apache ORC C++ library:
nvd
CVE-2018-8015P3HIGHCVSS 7.5≤ 1.4.32018-05-18
CVE-2018-8015 [HIGH] CWE-674 CVE-2018-8015: In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call i
In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack overflow might possibly corrupt the stack.
nvd
CVE-2024-40897P4MEDIUMCVSS 6.7≥ 0, < 1:0.4.39-12024-07-26
CVE-2024-40897 [MEDIUM] CVE-2024-40897: Stack-based buffer overflow vulnerability exists in orcparse
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
osv