Advisories for Cargo/Xxhash-Rust package

2026

xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release

I have a minimized safe Rust witness for xxhash-rust 0.8.15. Safe public route: xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[]) The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation. Observed diagnostic: Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference Local repair evidence: handling custom-secret slices shorter …