Skip to content

DEV-1424: Fix CVE-2026-82458 (unbounded allocation when decoding RDF Thrift) - #8

Merged
razvan-danit-tq merged 2 commits into
base-jena-6.2.0from
DEV-1424-thrift
Oct 5, 2026
Merged

razvan-danit-tq merged 2 commits into
base-jena-6.2.0from
DEV-1424-thrift

Conversation

@razvan-danit-tq

Copy link
Copy Markdown

Internal patched build of Apache Jena, published as 6.2.0-tq-3. Cumulative on top of 6.2.0-tq-2, so it keeps both TDB1 fixes (#5, #7).

CVE-2026-82458: the generated Thrift readers trusted a list's declared element count and pre-sized their ArrayList with it, so a few bytes of Thrift input could request an arbitrarily large allocation. In Jena that code is in jena-arq's generated org.apache.jena.riot.thrift.wire classes, not in libthrift, so upgrading the library alone does not remove it. Upstream Jena still ships classes generated by the 0.19.0 compiler.

This regenerates the wire package with the 0.25.0 compiler, which bounds the initial capacity with TBaseHelper.preallocSize. RDF_DataTuple and RDF_VarTuple, the two list readers, now use it. The rest of the wire diff is generator output only. ver.libthrift moves to 0.25.0 because the regenerated code calls TBaseHelper.preallocSize, which earlier libthrift versions lack.

Two commits: the POM version bump, then the regeneration plus the libthrift pin.

Validation

  • jena-arq: 16,559 tests, 0 failures (1 skipped).
  • jena-rdfpatch: 56 tests, 0 failures.
  • jena-tdb2: 865 tests, 0 failures (7 skipped). TDB2 stores its node table in this Thrift encoding, so this confirms the regenerated classes read and write the same format.

After merge: deploy all modules (including Fuseki) to Nexus, tag jena-6.2.0-tq-3, then bump ver.jena on TopBraid-Suite master.

🤖 Generated with Claude Code

razvan-danit-tq and others added 2 commits October 5, 2026 17:37
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CVE-2026-82458: the generated readers trusted a list's declared element count
and pre-sized their ArrayList with it, so a few bytes of Thrift input could
request an arbitrarily large allocation. That allocation lives in the
generated classes, not in libthrift, so upgrading the library alone does not
remove it. The 0.25.0 compiler bounds the initial capacity with
TBaseHelper.preallocSize; RDF_DataTuple and RDF_VarTuple, the two list
readers, now use it.

Regenerated with jena-arq/Grammar/RDF-Thrift/gen-thrift; everything else in
the wire package is generator output only. ver.libthrift moves to 0.25.0
because the regenerated code calls TBaseHelper.preallocSize, which earlier
libthrift versions lack.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@razvan-danit-tq
razvan-danit-tq marked this pull request as ready for review October 5, 2026 14:45
@razvan-danit-tq
razvan-danit-tq requested a review from cygri October 5, 2026 14:45
@razvan-danit-tq
razvan-danit-tq merged commit 37e9163 into base-jena-6.2.0 Oct 5, 2026
2 checks passed

@cygri cygri left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is already merged, but looks good to me anyway if the tests pass. Note nothing runs in CI so tests have to be run locally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants