—
RUSTSEC-2025-0018
Potential out-of-bounds read with a malformed ELF file and the HashTable API.
Details
Affected versions of this crate only validated the `index` argument of `HashTable::get_bucket` and `HashTable::get_chain` against the input-controlled `bucket_count` and `chain_count` fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/xmas-elf
Introduced in:
0.0.0-0Fixed in: 0.10.0Upgrade xmas-elf to 0.10.0 or newer (ecosystem crates.io).