RUSTSEC-2026-0117
Fragile bounds check when sampling from image
Details
A bounds check was performed in floating points before a cast to the index passed to an unchecked access function. This checked considered `NaN` cases improperly, causing them to succeed the check instead of failing it. The floating point coordinate is under caller control by passing a selected projection matrix.
Carefully controlling the coordinates of an image with no data and one non-zero dimension provides an arbitrary read primitive in the first 32-bits of address space with a Bilinear sampling method.
Using bicubic sampling can result in a read of a few bytes beyond an allocation.
Other out-of-bounds reads may be possible.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.23.1Upgrade imageproc to 0.23.1 or newer (ecosystem crates.io).