Repository navigation
Commit c7944b3
authored
### Rationale for this change
The bundled Apache Thrift dependency (0.22.0) is affected by
CVE-2026-55969, an integer overflow vulnerability in
`TTransport::checkReadBytesAvailable()` that could bypass message
size checks when reading maliciously crafted Thrift-encoded data.
Arrow's Parquet module relies on Thrift's compact protocol to
deserialize Parquet file metadata, so this is relevant to Arrow.
### What changes are included in this PR?
- Bump the bundled Apache Thrift version from 0.22.0 to 0.24.0 in
`cpp/thirdparty/versions.txt` (including the SHA256 checksum).
- Remove the Clang-only `thrift-3187.patch` and its application logic
in `ThirdpartyToolchain.cmake`. This patch pre-applied Thrift's
upstream fix for THRIFT-3268 (a compiler warning), which has since
been merged into Thrift itself and is already included in 0.24.0.
Keeping the patch would make `git apply`/`patch` fail during the
bundled build with Clang.
### Are these changes tested?
- Verified that `thrift-0.24.0.tar.gz` downloads correctly and its
SHA256 checksum matches the value published at
downloads.apache.org.
- Confirmed the CVE fix is present in Thrift 0.24.0 by diffing
`TProtocol.h`, `TCompactProtocol.h`, `TBinaryProtocol.h`, and
`TTransport.h` against 0.22.0.
- Confirmed `thrift-3187.patch` no longer applies cleanly against
0.24.0 sources (already fixed upstream), which is why it was
removed rather than kept as a no-op.
- Built Arrow C++ locally on macOS (arm64, AppleClang) with
`-DARROW_PARQUET=ON -DARROW_BUILD_TESTS=ON -DThrift_SOURCE=BUNDLED`,
on top of the latest `main` (after rebasing), and ran the following
Parquet tests. All of them passed with no failures (some tests were
skipped, e.g. those requiring Snappy, which was not enabled in my
build):
`parquet-internals-test`, `parquet-file-deserialize-test`,
`parquet-schema-test`, `parquet-reader-test`,
`parquet-writer-test`, `parquet-arrow-reader-writer-test`,
`parquet-arrow-metadata-test`, `parquet-arrow-index-test`, and
`parquet-arrow-internals-test`.
- Not tested locally: the removed patch was only applied for
`CMAKE_CXX_COMPILER_ID STREQUAL "Clang"`, which my AppleClang build
does not hit, so building the bundled Thrift with Clang on Linux
relies on CI. I also did not test encryption, Windows/MSVC, or the
Python/R packaging builds locally.
### Are there any user-facing changes?
No.
* GitHub Issue: #51354
---
Disclosure: this change was prepared with the assistance of an AI
coding tool (Claude Code). I reviewed the diff, verified the CVE fix
and checksum myself, and ran the test suite locally before opening
this PR.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Authored-by: Hanayoshi-8744 <201203709+Hanayoshi-8744@users.noreply.github.com>
Signed-off-by: Sutou Kouhei <kou@clear-code.com>
1 parent 6c82e24 commit c7944b3
3 files changed
Lines changed: 2 additions & 185 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1816 | 1816 | | |
1817 | 1817 | | |
1818 | 1818 | | |
1819 | | - | |
1820 | | - | |
1821 | | - | |
1822 | | - | |
1823 | | - | |
1824 | | - | |
1825 | | - | |
1826 | | - | |
1827 | | - | |
1828 | | - | |
1829 | | - | |
1830 | | - | |
1831 | | - | |
1832 | | - | |
1833 | | - | |
1834 | | - | |
1835 | | - | |
1836 | | - | |
1837 | | - | |
1838 | | - | |
1839 | 1819 | | |
1840 | 1820 | | |
1841 | | - | |
1842 | 1821 | | |
1843 | 1822 | | |
1844 | 1823 | | |
| |||
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
110 | 110 | | |
111 | 111 | | |
112 | 112 | | |
113 | | - | |
114 | | - | |
| 113 | + | |
| 114 | + | |
115 | 115 | | |
116 | 116 | | |
117 | 117 | | |
| |||
0 commit comments