RUSTSEC-2026-0302

Source
https://rustsec.org/advisories/RUSTSEC-2026-0302
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0302.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0302
Published
2026-09-22T12:00:00Z
Modified
2026-09-22T21:00:02Z
Summary
`stack-graphs` C API exports are safe `extern "C"` functions
Details

stack_graphs::c is a public module. From 0.0.3 through the current crates.io release 0.14.1, its pointer-taking entry points are pub extern "C" fn rather than unsafe fn. Safe Rust can call them.

sg_stack_graph_free frees the pointer with Box::from_raw. sg_stack_graph_free(std::ptr::null_mut()) is immediate undefined behavior. The same shape is used by the other *_free exports and by getters and mutators that dereference the caller-supplied pointer or pass it to from_raw_parts (sg_stack_graph_nodes, sg_stack_graph_add_edges, and the rest of the pointer-taking functions in src/c.rs). Constructors that take no pointer are not part of this issue.

The upstream repository is archived, so a fix cannot be filed there and no patched release exists. The soundness fix is to make every pointer-taking export unsafe extern "C" fn, with a safety comment that the pointer is non-null and, for free, came from the matching constructor.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / stack-graphs

Package

Name
stack-graphs
View open source insights on deps.dev
Purl
pkg:cargo/stack-graphs

Affected ranges

Type
SEMVER
Events
Introduced
0.0.3-0

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [
            "stack_graphs::c::sg_stack_graph_free"
        ],
        "os":  []
    }
}

Database specific

categories
[
    "memory-corruption"
]
cvss
null
informational
"unsound"
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0302.json"