Executive brief
faster-hex is a Rust library that provides optimized hexadecimal encoding and decoding functions. The `hex_decode_unchecked` function has a buffer over-read vulnerability in its AVX2 code path on x86/x86_64 processors, where it reads 64 bytes from the source buffer even when fewer bytes are available. While this primarily causes memory disclosure rather than direct code execution, applications that process untrusted hex data could leak sensitive information from adjacent memory regions.
Technical details
The `hex_decode_avx2` function performs a loop that checks `dst.len() >= 32` before loading 64 bytes (two 32-byte chunks) from the source buffer, but does not verify that `src.len() >= 64`. This allows callers to pass a short source buffer with a larger destination buffer, resulting in an out-of-bounds read on x86/x86_64 architectures when AVX2 is enabled. The vulnerability exists in versions 0.3.0 through 0.10.0; it is patched in 0.10.1 and later.
Affected products
- faster-hex faster-hex 0.3.0 through 0.10.0
Timeline
- 2026-09-20: disclosed
- 2026-09-23: patched: Version 0.10.1 released with backport fix