{"id":"GHSA-9cc5-2pq7-hfj8","aliases":["RUSTSEC-2025-0018"],"url":"https://o3.security/vulnerability/GHSA-9cc5-2pq7-hfj8","summary":"xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.","details":"Affected versions of this crate only validated the `index` argument of `HashTable::get_bucket` and `HashTable::get_chain` against the input-controlled `bucket_count` and `chain_count` fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.","published":"2025-03-26T20:11:24Z","modified":"2026-09-10T03:50:23.078536527Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"xmas-elf","fixedVersion":"0.10"}],"fix":{"url":"https://github.com/nrc/xmas-elf/commit/57685c35512a57269086314a42a70441af4ef451","label":"nrc/xmas-elf@57685c3"},"references":[{"type":"WEB","url":"https://github.com/nrc/xmas-elf/issues/86"},{"type":"WEB","url":"https://github.com/nrc/xmas-elf/commit/57685c35512a57269086314a42a70441af4ef451"},{"type":"PACKAGE","url":"https://github.com/nrc/xmas-elf"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0018.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:23.078536527Z"}}