GH-47803: [C++][Parquet] Fix read out of bounds on invalid RLE data#47804
Merged
pitrou merged 2 commits intoapache:mainfrom Oct 14, 2025
Merged
GH-47803: [C++][Parquet] Fix read out of bounds on invalid RLE data#47804pitrou merged 2 commits intoapache:mainfrom
pitrou merged 2 commits intoapache:mainfrom
Conversation
Member
Author
|
This is ready for review, but should not be merged before the regression file is added to the arrow-testing repo. @wgtmac @AntoinePrv @adamreeve |
adamreeve
approved these changes
Oct 13, 2025
wgtmac
approved these changes
Oct 14, 2025
Member
wgtmac
left a comment
There was a problem hiding this comment.
LGTM. Do we need to include it in the 22.0.0 release?
Member
Author
raulcd
pushed a commit
that referenced
this pull request
Oct 14, 2025
…47804) Found by OSS-Fuzz, should fix https://issues.oss-fuzz.com/issues/451150486. Ensure RLE run is within bounds before reading it. Yes, by fuzz regression test in ASAN/UBSAN build. No. **This PR contains a "Critical Fix".** (If the changes fix either (a) a security vulnerability, (b) a bug that caused incorrect or invalid data to be produced, or (c) a bug that causes a crash (even when the API contract is upheld), please provide explanation. If not, you can remove this.) * GitHub Issue: #47803 Authored-by: Antoine Pitrou <[email protected]> Signed-off-by: Antoine Pitrou <[email protected]>
Member
|
I've cherry-picked this for 22.0.0. |
|
After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit f83b301. There were no benchmark performance regressions. 🎉 The full Conbench report has more details. It also includes information about 40 possible false positives for unstable benchmarks that are known to sometimes produce them. |
zanmato1984
pushed a commit
to zanmato1984/arrow
that referenced
this pull request
Oct 15, 2025
…data (apache#47804) ### Rationale for this change Found by OSS-Fuzz, should fix https://issues.oss-fuzz.com/issues/451150486. ### What changes are included in this PR? Ensure RLE run is within bounds before reading it. ### Are these changes tested? Yes, by fuzz regression test in ASAN/UBSAN build. ### Are there any user-facing changes? No. **This PR contains a "Critical Fix".** (If the changes fix either (a) a security vulnerability, (b) a bug that caused incorrect or invalid data to be produced, or (c) a bug that causes a crash (even when the API contract is upheld), please provide explanation. If not, you can remove this.) * GitHub Issue: apache#47803 Authored-by: Antoine Pitrou <[email protected]> Signed-off-by: Antoine Pitrou <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rationale for this change
Found by OSS-Fuzz, should fix https://issues.oss-fuzz.com/issues/451150486.
What changes are included in this PR?
Ensure RLE run is within bounds before reading it.
Are these changes tested?
Yes, by fuzz regression test in ASAN/UBSAN build.
Are there any user-facing changes?
No.
This PR contains a "Critical Fix". (If the changes fix either (a) a security vulnerability, (b) a bug that caused incorrect or invalid data to be produced, or (c) a bug that causes a crash (even when the API contract is upheld), please provide explanation. If not, you can remove this.)