VDB
Sign up
—

RUSTSEC-2026-0117

Fragile bounds check when sampling from image

Details

A bounds check was performed in floating points before a cast to the index passed to an unchecked access function. This checked considered `NaN` cases improperly, causing them to succeed the check instead of failing it. The floating point coordinate is under caller control by passing a selected projection matrix.

Carefully controlling the coordinates of an image with no data and one non-zero dimension provides an arbitrary read primitive in the first 32-bits of address space with a Bilinear sampling method.

Using bicubic sampling can result in a read of a few bytes beyond an allocation.

Other out-of-bounds reads may be possible.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/imageproc
Introduced in: 0.0.0-0Fixed in: 0.23.1

Upgrade imageproc to 0.23.1 or newer (ecosystem crates.io).

References