VDB
Sign up
—

RUSTSEC-2025-0018

Potential out-of-bounds read with a malformed ELF file and the HashTable API.

Details

Affected versions of this crate only validated the `index` argument of `HashTable::get_bucket` and `HashTable::get_chain` against the input-controlled `bucket_count` and `chain_count` fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/xmas-elf
Introduced in: 0.0.0-0Fixed in: 0.10.0

Upgrade xmas-elf to 0.10.0 or newer (ecosystem crates.io).

References