CoolFace
Modelpublic

ChristianTeroerde/orc-rlev2-patched-base-oob-poc

sourceHugging Faceapache-2.0updated 3mo agoView on Hugging Face
0likes
Model Card

PoC: Out-of-bounds heap read in Apache ORC C++ (RLEv2 PATCHED_BASE)

Responsible-disclosure proof-of-concept submitted via huntr.

evil.orc (115 bytes) is a crafted Apache ORC file: one LONG column whose RLEv2 PATCHED_BASE data stream sets pl=31 with every patch entry gap=255 / patch=0, driving RleDecoderV2::adjustGapAndPatch to walk unpackedPatch_[idx] past the 248-byte buffer end → out-of-bounds heap read (CWE-125) in the stock reader (createReader → IntegerColumnReader → RleDecoderV2::nextPatched).

Benign marker only (read past a heap buffer; no code execution, no payload). For maintainers: bound the gap-walk against unpackedPatch_.size(). Repro: build apache/orc with -fsanitize=address -DBUILD_TOOLS=ON, run orc-contents evil.orc.