ChristianTeroerde/orc-rlev2-patched-base-oob-poc
0
PoC: Out-of-bounds heap read in Apache ORC C++ (RLEv2 PATCHED_BASE)
Responsible-disclosure proof-of-concept submitted via huntr.
evil.orc (115 bytes) is a crafted Apache ORC file: one LONG column whose RLEv2 PATCHED_BASE data stream sets pl=31 with every patch entry gap=255 / patch=0, driving RleDecoderV2::adjustGapAndPatch to walk unpackedPatch_[idx] past the 248-byte buffer end → out-of-bounds heap read (CWE-125) in the stock reader (createReader → IntegerColumnReader → RleDecoderV2::nextPatched).
Benign marker only (read past a heap buffer; no code execution, no payload). For maintainers: bound the gap-walk against unpackedPatch_.size(). Repro: build apache/orc with -fsanitize=address -DBUILD_TOOLS=ON, run orc-contents evil.orc.
