Repository navigation
DEV-1424: Fix CVE-2026-82458 (unbounded allocation when decoding RDF Thrift) - #8
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CVE-2026-82458: the generated readers trusted a list's declared element count and pre-sized their ArrayList with it, so a few bytes of Thrift input could request an arbitrarily large allocation. That allocation lives in the generated classes, not in libthrift, so upgrading the library alone does not remove it. The 0.25.0 compiler bounds the initial capacity with TBaseHelper.preallocSize; RDF_DataTuple and RDF_VarTuple, the two list readers, now use it. Regenerated with jena-arq/Grammar/RDF-Thrift/gen-thrift; everything else in the wire package is generator output only. ver.libthrift moves to 0.25.0 because the regenerated code calls TBaseHelper.preallocSize, which earlier libthrift versions lack. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cygri
approved these changes
Oct 6, 2026
cygri
left a comment
There was a problem hiding this comment.
This is already merged, but looks good to me anyway if the tests pass. Note nothing runs in CI so tests have to be run locally.
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Internal patched build of Apache Jena, published as
6.2.0-tq-3. Cumulative on top of6.2.0-tq-2, so it keeps both TDB1 fixes (#5, #7).CVE-2026-82458: the generated Thrift readers trusted a list's declared element count and pre-sized their
ArrayListwith it, so a few bytes of Thrift input could request an arbitrarily large allocation. In Jena that code is injena-arq's generatedorg.apache.jena.riot.thrift.wireclasses, not in libthrift, so upgrading the library alone does not remove it. Upstream Jena still ships classes generated by the 0.19.0 compiler.This regenerates the wire package with the 0.25.0 compiler, which bounds the initial capacity with
TBaseHelper.preallocSize.RDF_DataTupleandRDF_VarTuple, the two list readers, now use it. The rest of the wire diff is generator output only.ver.libthriftmoves to 0.25.0 because the regenerated code callsTBaseHelper.preallocSize, which earlier libthrift versions lack.Two commits: the POM version bump, then the regeneration plus the libthrift pin.
Validation
After merge: deploy all modules (including Fuseki) to Nexus, tag
jena-6.2.0-tq-3, then bumpver.jenaon TopBraid-Suite master.🤖 Generated with Claude Code