---
id: CVE-2025-48431
title: >-
  Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib
  language bindings.


  This issue affects Apache Thrift: before 0.23.0.


  Users are recommended to upgrade to version 0.23.0, which fixes the issue.


  Description: Sp…
summary: >-
  Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib
  language bindings.


  This issue affects Apache Thrift: before 0.23.0.


  Users are recommended to upgrade to version 0.23.0, which fixes the issue.


  Description: Sp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-762
  - CWE-763
vendor: apache
product: thrift
affected:
  - thrift < 0.23.0
patched:
  - thrift 0.23.0
published: '2026-04-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:16:58.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48431'
references:
  - url: 'https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/28/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:24539'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25273'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27126'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28010'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36882'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2025-48431'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2463410'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48431.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-48431'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48431'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-28T13:54:53.014882Z'
epss: 0.01079
epssPercentile: 0.63643
ingestedAt: '2026-07-01T15:50:58.798Z'
---

## Overview

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

## Affected

- `thrift < 0.23.0`

## Remediation

Upgrade past the affected range:

- `thrift 0.23.0`

## Vendor advisories

- **RHSA-2026:28010** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28010)
- **RHSA-2026:36882** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36882)
- **RHSA-2026:24539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24539)
- **RHSA-2026:25273** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:25273)
- **RHSA-2026:27126** · Red Hat · fixed in: Red Hat OpenShift distributed tracing 3.10.2 · released 2026-06-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:27126)
- **Red Hat VEX** · Important · affected: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat AI Inference Server, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · no fix planned: Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48431.json)
