{"id":"GHSA-9cc5-2pq7-hfj8","summary":"xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.","details":"Affected versions of this crate only validated the `index` argument of `HashTable::get_bucket` and `HashTable::get_chain` against the input-controlled `bucket_count` and `chain_count` fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.","aliases":["RUSTSEC-2025-0018"],"modified":"2026-09-10T03:50:23.078536527Z","published":"2025-03-26T20:11:24Z","database_specific":{"cwe_ids":["CWE-125"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-03-26T20:11:24Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/nrc/xmas-elf/issues/86"},{"type":"WEB","url":"https://github.com/nrc/xmas-elf/commit/57685c35512a57269086314a42a70441af4ef451"},{"type":"PACKAGE","url":"https://github.com/nrc/xmas-elf"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0018.html"}],"affected":[{"package":{"name":"xmas-elf","ecosystem":"crates.io","purl":"pkg:cargo/xmas-elf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-9cc5-2pq7-hfj8/GHSA-9cc5-2pq7-hfj8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}