CVE-2026-92612 - Eclipse iceoryx2 StaticString Memory Safety Vulnerability
CVE ID :CVE-2026-92612
Published : Sept. 21, 2026, 10:47 a.m. | 22 minutes ago
Description :In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Severity: 1.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 21, 2026, 10:47 a.m. | 22 minutes ago
Description :In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Severity: 1.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...