WARNING: SECURITY RESEARCH β€” PROOF OF CONCEPT ONLY

This repository contains malformed/crafted Apache ORC files that trigger crashes (unbounded allocation, integer overflow) in ORC's C++ reader (DictionaryLoader.cc / ColumnReader.cc / StripeStream.cc). These are passive data files, not executable code β€” they do nothing on their own and only cause a crash/OOM/OOB-read when parsed by orc::createReader() / RowReader::next().

DO NOT load these files with a production ORC build outside of an isolated, disposable research environment (memory exhaustion and memory-safety risk).

Findings Summary

File Finding CWE Confirmation Location
dictionary_wraparound_poc.orc Integer wraparound β†’ zero-capacity buffer CWE-190 Prior art (EnigmaConsultant), included for reference DictionaryLoader.cc:67
dictionary_unbounded_alloc_poc.orc Unbounded allocation (~34GB) CWE-789 Fuzz-confirmed (1M+ execs, 6.5h) DictionaryLoader.cc:67
string_vectorbatch_resize_poc.orc Unbounded allocation (StringVectorBatch) CWE-789 Fuzz-confirmed ColumnReader.cc:743
string_direct_reader_resize_poc.orc Unbounded allocation (StringDirectColumnReader) CWE-789 Fuzz-confirmed ColumnReader.cc:743
stripestream_offset_overflow_poc.orc Integer overflow β†’ OOB read CWE-190/CWE-125 Manually-confirmed (protobuf-valid PoC) StripeStream.cc:94

Note: dictionary_wraparound_poc.orc reproduces a previously-documented finding by EnigmaConsultant (HuggingFace: EnigmaConsultant/orc-dictionary-overflow) and is included here only for completeness/context, not as a novel claim. The other four files represent this report's independent contributions.

Reproduction

# Build ORC C++ from source (HEAD a6f12fd)
# Compile with ASan+UBSan for crash detection
clang++ -std=c++17 -fsanitize=address,undefined -g -O1 \
    -I/path/to/orc/c++/include -I/path/to/orc/build/c++/include \
    -c fuzzer_harness.cc -o fuzzer_harness.o

clang++ -fsanitize=address,undefined -g -O1 \
    fuzzer_harness.o /path/to/orc/build/c++/src/liborc.a \
    /path/to/orc/build/_deps/protobuf-build/liborc_vendored_protobuf.a \
    /path/to/orc/build/_deps/snappy-build/liborc_vendored_snappy.a \
    /path/to/orc/build/_deps/zstd-build/lib/liborc_vendored_zstd.a \
    /path/to/orc/build/_deps/lz4-build/liborc_vendored_lz4.a \
    /path/to/orc/build/_deps/zlib-build/liborc_vendored_zlib.a \
    -lz -ldl -lpthread -o fuzzer_harness

# Test each PoC
./fuzzer_harness dictionary_unbounded_alloc_poc.orc

A minimal fuzzer harness that calls orc::createReader() + RowReader::next() is sufficient to reproduce all findings.

Full Report

See report.md in this repository for the complete vulnerability report with ASan stack traces, root cause analysis, and code-level detail per finding.

Credits

  • @drogba771 β€” Discovery, fuzzing, PoC, analysis
  • EnigmaConsultant β€” Prior art for the wraparound scenario (CWE-190)

Timeline

  • 2026-07-19: Fuzzing campaign (6.5h, 3 AFL++ workers, 1M+ execs)
  • 2026-07-19: All 4 findings confirmed
Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support