PT-2025-13025 · Crates.Io · Xmas-Elf

Published

2025-03-26

·

Updated

2025-03-26

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Affected versions of this crate only validated the index argument of HashTable::get bucket and HashTable::get chain against the input-controlled bucket count and chain count fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2025-0018

Affected Products

Xmas-Elf