PT-2026-96070 · Eclipse · Iceoryx2

CVE-2026-92612

·

Published

2026-09-18

·

Updated

2026-09-21

CVSS v4.0

1.0

Low

VectorAV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Eclipse iceoryx2 versions greater than v0.8.0
Description The StaticString component exposes its contents as mutable bytes through safe APIs. The String::as str() function converts these bytes into a Rust string slice without validating UTF-8 encoding. This allows an application to create an invalid &str and trigger undefined behavior using safe Rust. The issue specifically involves the as mut bytes and deref mut methods within the String API and its implementations, including PolymorphicString, RelocatableString, and StaticString.
Recommendations Update Eclipse iceoryx2 to a version where the as mut bytes and deref mut methods have been removed from the String API.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92612
GHSA-8MQ4-3MWQ-QVG6
RUSTSEC-2026-0294

Affected Products

Iceoryx2