PT-2026-105968 · Crates.Io · Stack-Graphs

Publicado

2026-09-22

·

Atualizado

2026-09-22

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
stack graphs::c is a public module. From 0.0.3 through the current crates.io release 0.14.1, its pointer-taking entry points are pub extern "C" fn rather than unsafe fn. Safe Rust can call them.
sg stack graph free frees the pointer with Box::from raw. sg stack graph free(std::ptr::null mut()) is immediate undefined behavior. The same shape is used by the other * free exports and by getters and mutators that dereference the caller-supplied pointer or pass it to from raw parts (sg stack graph nodes, sg stack graph add edges, and the rest of the pointer-taking functions in src/c.rs). Constructors that take no pointer are not part of this issue.
The upstream repository is archived, so a fix cannot be filed there and no patched release exists. The soundness fix is to make every pointer-taking export unsafe extern "C" fn, with a safety comment that the pointer is non-null and, for free, came from the matching constructor.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

RUSTSEC-2026-0302

Produtos afetados

Stack-Graphs