GHSA-6g2r-675j-hx59: Low severity rust/xxhash-rust vulnerability
I have a minimized safe Rust witness for xxhash-rust 0.8.15.
Safe public route:
xxhashrust::xxh3::xxh364withsecret(&[0x41], &[])
The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debugassert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.
Observed diagnostic:
Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference
Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.
Local artifacts: - vulnerable log: artifacts/logs/W-4332xxhashrustshortsecretmirireleaselinux001.log - repair log: artifacts/logs/differentials/W-4332xxhashrustlocalrepairmirireleaselinux001.log - report: artifacts/reports/W-4332xxhashrustshortsecretreport.md
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/xxhash-rustto a version that resolves this vulnerability.Fixed in 0.8.16 - Compensating control
Before calling xxhash_rust::xxh3::xxh3_64_with_secret, reject or otherwise handle custom-secret slices shorter than the internal minimum so fixed-width secret reads are not performed beyond the secret allocation.
Event History
Frequently Asked Questions
What input is required to trigger the issue?
A caller must invoke xxhash_rust::xxh3::xxh3_64_with_secret with a custom secret shorter than the internal minimum, such as an empty slice. The reported witness uses a one-byte input and an empty secret.
Can this be reached through safe Rust code?
Yes. The reported call path is a public safe API, and the caller-side harness contains no unsafe code. In release execution, the short-secret check is only enforced by a debug assertion before fixed-width secret reads occur.
Who is realistically exposed?
Applications using xxhash-rust 0.8.15 that call the XXH3 custom-secret hashing API with caller-controlled or otherwise undersized secret slices are exposed. Uses that do not provide a custom secret, or that ensure secrets meet the internal minimum length, are not described as affected by this report.
What can be done if updating is not immediately possible?
Validate custom-secret lengths before calling the affected API and reject or avoid secrets shorter than the required internal minimum. The provided repair evidence indicates that handling undersized custom-secret slices before fixed-width secret reads prevents the reported release-Miri failure.