GHSA-6g2r-675j-hx59: Low severity rust/xxhash-rust vulnerability

Published Oct 2, 2026
·
Updated

I have a minimized safe Rust witness for xxhash-rust 0.8.15.

Safe public route:

xxhashrust::xxh3::xxh364withsecret(&[0x41], &[])

The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debugassert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.

Observed diagnostic:

Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference

Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.

Local artifacts: - vulnerable log: artifacts/logs/W-4332xxhashrustshortsecretmirireleaselinux001.log - repair log: artifacts/logs/differentials/W-4332xxhashrustlocalrepairmirireleaselinux001.log - report: artifacts/reports/W-4332xxhashrustshortsecretreport.md

Affected Software

1 affected componentFixes available
rust/xxhash-rust<0.8.16
0.8.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/xxhash-rust to a version that resolves this vulnerability.

    Fixed in 0.8.16
  2. Compensating control

    Before calling xxhash_rust::xxh3::xxh3_64_with_secret, reject or otherwise handle custom-secret slices shorter than the internal minimum so fixed-width secret reads are not performed beyond the secret allocation.

Event History

Oct 2, 2026
Advisory Published
via GitHub·06:29 PM
Data Sourced
via GitHub·06:29 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What input is required to trigger the issue?

A caller must invoke xxhash_rust::xxh3::xxh3_64_with_secret with a custom secret shorter than the internal minimum, such as an empty slice. The reported witness uses a one-byte input and an empty secret.

2

Can this be reached through safe Rust code?

Yes. The reported call path is a public safe API, and the caller-side harness contains no unsafe code. In release execution, the short-secret check is only enforced by a debug assertion before fixed-width secret reads occur.

3

Who is realistically exposed?

Applications using xxhash-rust 0.8.15 that call the XXH3 custom-secret hashing API with caller-controlled or otherwise undersized secret slices are exposed. Uses that do not provide a custom secret, or that ensure secrets meet the internal minimum length, are not described as affected by this report.

4

What can be done if updating is not immediately possible?

Validate custom-secret lengths before calling the affected API and reject or avoid secrets shorter than the required internal minimum. The provided repair evidence indicates that handling undersized custom-secret slices before fixed-width secret reads prevents the reported release-Miri failure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203