Vulnerability GHSA-6g2r-675j-hx59
Summary
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
Details
I have a minimized safe Rust witness for xxhash-rust 0.8.15.
Safe public route:
xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[])
The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.
Observed diagnostic:
Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference
Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.
Local artifacts:
- vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log
- repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log
- report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md