Arawoof06 opened a new issue, #1317:
URL: https://github.com/apache/arrow-java/issues/1317

   ### Describe the bug
   
   `ArrowMessage.frame` deserializes incoming `FlightData` frames. It is 
installed as the gRPC request marshaller for `DoPut` and `DoExchange` 
(`FlightBindingService`), so it runs server-side on bytes from any connected 
client.
   
   For each wire field it reads a length prefix with `readRawVarint32` and then 
allocates that many bytes before reading any content:
   
   - `DESCRIPTOR_TAG` / `HEADER_TAG`: `byte[] bytes = new byte[size];`
   - `APP_METADATA_TAG` / `BODY_TAG`: `allocator.buffer(size);`
   
   `size` comes straight off the wire and is never checked against the bytes 
actually present. The `new byte[size]` paths allocate on the JVM heap and 
bypass the `BufferAllocator` limit entirely, so a tiny crafted frame declaring 
a length near `Integer.MAX_VALUE` forces a multi-gigabyte allocation 
(OutOfMemoryError / GC thrash) during request deframing, before the application 
sees or authenticates the stream.
   
   A field can never be longer than the bytes still buffered for the message, 
so the declared length can be validated against `stream.available()` (the frame 
parser already relies on `available()` as its loop guard).
   
   ### Component(s)
   
   Java, FlightRPC


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to