目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-25087— Apache Arrow 安全漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache Arrow
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache Arrow是美国阿帕奇(Apache)基金会的一款用于内存数据处理的跨语言开发平台。该平台支持C、C++、C#、Go和Java等编程语言,并提供进程间通信等功能。 Apache Arrow 15.0.0版本至23.0.0版本存在安全漏洞,该漏洞源于读取包含可变缓冲区的Arrow IPC文件时可能触发释放后重用,可能导致随机崩溃、内存损坏或拒绝服务攻击。

AI 预测 5.5 利用难度: 困难 EPSS 0.82% · P56
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-25087 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
来源: CVE Program / CVE List V5
Vulnerability Description
Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shared_ptr<Buffer>` object) that is written to the dangling pointer is not under direct control of the attacker. Pre-buffering is disabled by default but can be enabled using a specific C++ API call (`RecordBatchFileReader::PreBufferMetadata`). The functionality is not exposed in language bindings (Python, Ruby, C GLib), so these bindings are not vulnerable. The most likely consequence of this issue would be random crashes or memory corruption when reading specific kinds of IPC files. If the application allows ingesting IPC files from untrusted sources, this could plausibly be exploited for denial of service. Inducing more targeted kinds of misbehavior (such as confidential data extraction from the running process) depends on memory allocation and multi-threaded IO temporal patterns that are unlikely to be easily controlled by an attacker. Advice for users of Arrow C++: 1. check whether you enable pre-buffering on the IPC file reader (using `RecordBatchFileReader::PreBufferMetadata`) 2. if so, either disable pre-buffering (which may have adverse performance consequences), or switch to Arrow 23.0.1 which is not vulnerable
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
释放后使用
来源: CVE Program / CVE List V5
Vulnerability Title
Apache Arrow 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Apache Arrow是美国阿帕奇(Apache)基金会的一款用于内存数据处理的跨语言开发平台。该平台支持C、C++、C#、Go和Java等编程语言,并提供进程间通信等功能。 Apache Arrow 15.0.0版本至23.0.0版本存在安全漏洞,该漏洞源于读取包含可变缓冲区的Arrow IPC文件时可能触发释放后重用,可能导致随机崩溃、内存损坏或拒绝服务攻击。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache Arrow 15.0.0 ~ 23.0.0 -

二、漏洞 CVE-2026-25087 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-25087 的情报信息

请登录查看更多情报信息。

同批安全公告 · Apache Software Foundation · 2026-02-17 · 共 5 条

CVE-2026-24734 Apache Tomcat和Apache Tomcat Native 输入验证错误漏洞
CVE-2026-24733 Apache Tomcat 输入验证错误漏洞
CVE-2025-66614 Apache Tomcat 输入验证错误漏洞
CVE-2026-25903 Apache NiFi 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-25087

暂无评论


发表评论