PT-2026-109643 · Apache · Apache Datasketches
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Apache DataSketches C++ versions 2.0.0-incubating through 5.2.9
Description
An out-of-bounds read exists in the VarOpt union deserialization process. The
var opt union::deserialize() function reads a 32-byte preamble from a non-empty union even when only 8 bytes are available, potentially reading up to 24 bytes beyond the input end. Additionally, an unsigned subtraction used to calculate the remaining size for the embedded sketch can wrap around, bypassing subsequent size checks. This allows bytes from adjacent memory to be incorporated into the deserialized union state, which may lead to a crash (denial of service) or the exposure of memory contents. This issue specifically affects applications that deserialize VarOpt unions from untrusted sources.Recommendations
Upgrade to version 5.3.0.
DoS
Out of bounds Read
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Datasketches