PT-2026-105471 · Crates.Io · Yara-X
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
[!NOTE] This finding was identified during an agentic unsafe Rust code review performed by Gemini AI, followed by human review and verification.
The Issue
The crate exports a public safe API
Rules::deserialize accepting any generic byte sequence B: AsRef<[u8]>. It restores compiled rule structures directly from raw bytes using bincode::serde::decode from slice.This decoded
Rules struct contains internal lookup tables, including sub patterns: Vec<(PatternId, SubPattern)>, atoms: Vec<SubPatternAtom>, and lit pool: BStringPool. Subsequent safe operations assume these internal tables satisfy strict structural invariants:Rules::get sub patternexecutesunsafe { self.sub patterns.get unchecked(sub pattern id.0 as usize) }. If untrusted serialized bytes contain an atom referencing an out-of-boundsSubPatternId, callingget sub patternduring scanning triggers an out-of-bounds memory read (Undefined Behavior).
Metadata::next()extracts string metadata viaunsafe { s.to str unchecked() }. If serialized bytes corruptlit poolindices or structural data,to str uncheckedconstructs a&strpointing to invalid UTF-8 bytes (Undefined Behavior).
Because passing malformed or untrusted data to
Rules::deserialize induces Undefined Behavior in subsequent safe calls (Scanner::new, Scanner::scan) without any unsafe blocks in caller code, this API is unsound.Minimal Reproduction (Miri / Native Crash)
Zip file with crashing payload:
[crashing payload.zip](https://github.com/user-attachments/files/29173221/crashing payload.zip)
We have a payload crashing payload.bin where only a single byte in the structural metadata tail is mutated (changing a
SubPatternId from 1 to 248 while keeping the WebAssembly bytecode completely untouched and valid).Below is the self-contained verification script which compiles and runs against the official unmodified
yara-x v1.17.0 crate:rust
use yara x::{Rules, Scanner};
fn main() {
// Embed the crashing payload generated by the fuzzer at compile time.
let serialized = include bytes!("crashing payload.bin");
println!("Loaded embedded crashing payload, length: {}", serialized.len());
// Deserialize. On unmodified library, this succeeds because the WASM and headers
// are pristine and structural corruption isn't validated.
if let Ok(deserialized) = Rules::deserialize(serialized) {
println!("Deserialization succeeded! Running scanner...");
let mut scanner = Scanner::new(&deserialized);
// Run the standard scan, which will execute the WASM and trigger the out-of-bounds read!
let = scanner.scan(b"lorem ipsum dolor sit amet");
println!("Scanner finished.");
} else {
println!("Deserialization failed!");
}
}1. Miri Trace
NOTE: This needs to be run with 1.17.0. I haven't tested this against other versions.
Unfortunately I was able to get a miri trace, but I'm not able to reproduce it right now because of lockfile changes. If you're trying this out be sure to use
MIRIFLAGS="-Zmiri-disable-stacked-borrows"2. Segfault / panics
When run natively (without Miri or any sanitizers) on a standard Linux platform, the process immediately segfaults:
bash
$ cargo run --bin verify
Loaded embedded crashing payload, length: 11777
Deserialization succeeded! Running scanner...
Segmentation fault (core dumped)And with a newer compiler (which appears to have debug assertions in
get unchecked)bash
Deserialization succeeded! Running scanner...
thread 'main' (997442) panicked at lib/src/compiler/rules.rs:404:36:
unsafe precondition(s) violated: slice::get unchecked requires that the index is within the slice
This indicates a bug in the program. This Undefined Behavior check is optional, and cannot be relied on for safety.
note: run with `RUST BACKTRACE=1` environment variable to display a backtraceSuggested Fix
To uphold Rust soundness guarantees, either mark
Rules::deserialize as pub unsafe fn deserialize with a formal /// # Safety contract documenting that callers are responsible for verifying the authenticity and structural integrity of the input bytes (e.g. via cryptographic signatures), or replace all internal get unchecked and to str unchecked calls on deserialized data structures with safe bounds checks (.get()) and UTF-8 validation (std::str::from utf8).Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yara-X