debian · CVE-2024-40897

Quick triage

Priority: not yet assigned Published: Updated: Sun, 19 Jul 2026 12:01:35 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2024-40897 not yet assigned priority: Debian including 1 source packages (orc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2.

Description:

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

cvelogic Threat Intelligence