MODERATEcrates.io →
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
Affected packages
- xmas-elf— before 0.10
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/nrc/xmas-elf/issues/86
- https://github.com/nrc/xmas-elf/commit/57685c35512a57269086314a42a70441af4ef451
- https://github.com/nrc/xmas-elf
- https://rustsec.org/advisories/RUSTSEC-2025-0018.html
Structured record: https://osv.dev/vulnerability/GHSA-9cc5-2pq7-hfj8
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta