CVE-2026-35559: Out-of-bounds write in query processing components in Amazon Athena ODBC driver
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations.
To remediate this issue, users should upgrade to version 2.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driverto a version that resolves this vulnerability.Fixed in 2.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35559?
CVE-2026-35559 has a high severity level due to the potential for a threat actor to crash the Amazon Athena ODBC driver.
How do I fix CVE-2026-35559?
To mitigate CVE-2026-35559, update the Amazon Athena ODBC driver to version 2.1.0.0 or later.
Which versions of Amazon Athena ODBC driver are affected by CVE-2026-35559?
CVE-2026-35559 affects versions of the Amazon Athena ODBC driver prior to 2.1.0.0.
What components are impacted by CVE-2026-35559?
CVE-2026-35559 impacts the query processing components of the Amazon Athena ODBC driver.
Can CVE-2026-35559 be exploited remotely?
Yes, CVE-2026-35559 can be exploited remotely by a threat actor using specially crafted data.