GHSA-6g2r-675j-hx59
I have a minimized safe Rust witness for xxhash-rust 0.8.15. Safe public route: xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[]) The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation. Observed diagnostic: Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri. Local artifacts: - vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log - repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log - report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md
Properties
- severity
- low
- summary
- xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
- cvss_score
- 2.3
- retrieved_at
- 2026-10-02T19:33:52+00:00
- ghsa_published
- 2026-10-02T18:29:13Z
- source_url
- https://github.com/advisories/GHSA-6g2r-675j-hx59
- ghsa_updated
- 2026-10-02T18:29:16Z
- ghsa_id
- GHSA-6g2r-675j-hx59
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-6g2r-675j-hx59
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- signal_observed_at
- 2026-10-02T19:33:52+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph