yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-43868
Component Overview
Vulnerability Overview
Name
CVE-2026-43868
Source
NVD (
link
)
Debian (
link
)
Description
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CWEs
CWE-789
CWE-789
CWE-1285
Published Date
May 5, 2026
Updated Date
Jul 21, 2026
Workaround
-
Advisories
https://lists.apache.org/thread/zj76dtwnbbs1m7z3focf4wd51pqpsmn9
Vendor Advisory
Analysis
#
Affected Component
Analysis
thrift
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
thrift
buildroot
2025.02.x
0.23.0
Not Affected
thrift
buildroot
master
0.23.0
Not Affected
thrift
yocto
master
0.24.0
Not Affected
thrift
yocto
scarthgap
0.20.0
Patched
Resolved with patches
#
thrift (yocto:scarthgap)
#
Title
Author
Resolve
1
[THRIFT-5871] Add message / container size checking for Rust
Hasnain Lakhani <m.hasnain.lakhani@gmail.com>
CVE-2026-43868