CVE-2025-48431: Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
Apache Thrift: Specially crafted input can crash a cglib Thrift server with invalid pointer error.
Other sources
Mismatched Memory Management Routines vulnerability in Apache Thrift cglib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Description: Specially crafted requests can crash an cglib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thrift (c_glib language bindings)to a version that resolves this vulnerability.Fixed in 0.23.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48431?
CVE-2025-48431 has not been assigned a CVSS score, but it is a critical vulnerability that can lead to server crashes.
How do I fix CVE-2025-48431?
To fix CVE-2025-48431, upgrade your Apache Thrift c_glib to version 0.23.0 or later.
Which versions of Apache Thrift are affected by CVE-2025-48431?
CVE-2025-48431 affects all versions of Apache Thrift c_glib prior to 0.23.0.
What type of vulnerability is CVE-2025-48431?
CVE-2025-48431 is a mismatched memory management routines vulnerability that can cause server crashes.
What codebase is impacted by CVE-2025-48431?
CVE-2025-48431 specifically impacts the Apache Thrift c_glib language bindings.