RUSTSEC-2026-0234

Source
https://rustsec.org/advisories/RUSTSEC-2026-0234
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0234.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0234
Published
2026-05-11T12:00:00Z
Modified
2026-08-04T09:30:04.411453104Z
Summary
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Details

The archive validator could accept certain malformed relative pointers and invalid ArchivedHashTable states. In particular, the hash table verifier did not ensure that the number of occupied buckets matched the table's declared length.

A crafted archive could pass the checks performed by the safe rkyv::access and rkyv::from_bytes APIs and then cause an out-of-bounds read in later validation, lookup, or deserialization. Depending on the input, this could perform scalar or SIMD reads outside the archive buffer or crash the process.

Version 0.8.17 strengthens archive range validation and rejects hash tables whose number of occupied buckets does not match their declared length. Users who process untrusted archives should upgrade to 0.8.17 or later.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / rkyv

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.8.0-rc.1
Fixed
0.8.17

Ecosystem specific

{
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    },
    "affected_functions": null
}

Database specific

source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0234.json"
categories
[
    "memory-exposure",
    "denial-of-service"
]
cvss
null
informational
null