Skip to content

chore(deps): update rust crate xxhash-rust to v0.8.16 [security] - #78

Merged
fylorn merged 1 commit into
devfrom
renovate/crate-xxhash-rust-vulnerability
Oct 6, 2026
Merged

fylorn merged 1 commit into
devfrom
renovate/crate-xxhash-rust-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
xxhash-rust workspace.dependencies patch 0.8.15 → 0.8.16

xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release

GHSA-6g2r-675j-hx59

More information

Details

I have a minimized safe Rust witness for xxhash-rust 0.8.15.

Safe public route:

xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[])

The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.

Observed diagnostic:

Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference

Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.

Local artifacts:

  • vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log
  • repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log
  • report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md

Severity

  • CVSS Score: 2.3 / 10 (Low)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@fylorn
fylorn merged commit 0682864 into dev Oct 6, 2026
6 checks passed
@fylorn
fylorn deleted the renovate/crate-xxhash-rust-vulnerability branch October 6, 2026 01:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant