VDB
Sign up
LOW

GHSA-66fw-43h8-f8p3

XMP Toolkit's `XmpFile::close` can trigger undefined behavior

Details

Affected versions of the crate failed to catch C++ exceptions raised within the `XmpFile::close` function. If such an exception occurred, it would trigger undefined behavior, typically a process abort.

This is best demonstrated in [issue #230](https://github.com/adobe/xmp-toolkit-rs/issues/230), where a race condition causes the `close` call to fail due to file I/O errors.

This was fixed in [PR #232](https://github.com/adobe/xmp-toolkit-rs/pull/232) (released as crate version 1.9.0), which now safely handles the exception.

For backward compatibility, the existing API ignores the error. A new API `XmpFile::try_close` was added to allow callers to receive and process the error result.

Users of all prior versions of `xmp_toolkit` are encouraged to update to version 1.9.0 to avoid undefined behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/xmp_toolkit
Introduced in: 0Fixed in: 1.9.0

Upgrade xmp_toolkit to 1.9.0 or newer (ecosystem crates.io).

References