GHSA-6g2r-675j-hx59LowCVSS 2.3Disclosed before NVD

xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release

Published
October 2, 2026
Last Modified
October 2, 2026

📋 Description

I have a minimized safe Rust witness for xxhash-rust 0.8.15.

Safe public route:

xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[])

The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.

Observed diagnostic:

Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference

Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.

Local artifacts:

  • vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log
  • repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log
  • report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md

🎯 Affected products1

  • rust/xxhash-rust:< 0.8.16

🔗 References (3)