Arrow2 allows out of bounds access in public safe API
High severity
GitHub Reviewed
Published
May 30, 2025
to the GitHub Advisory Database
•
Updated May 30, 2025
Description
Published to the GitHub Advisory Database
May 30, 2025
Reviewed
May 30, 2025
Last updated
May 30, 2025
Rows::row_unchecked()
allows out of bounds access to the underlying buffer without sufficient checks.The arrow2 crate is no longer maintained, so there are no plans to fix this issue. Users are advised to migrate to the arrow crate, instead.
References