Junglewise Threat Intelligence

CVE-2026-92612: Eclipse iceoryx2 unsafe string handling in StaticString

CVE-2026-92612 · Severity: info · Published 2026-09-21

Vendors: crates.io, Eclipse.

Executive brief

Eclipse iceoryx2, a real-time inter-process communication middleware, exposes a vulnerability where the StaticString component allows safe Rust code to create invalid string objects by accessing mutable bytes without UTF-8 validation. This can trigger undefined behavior in applications using the library, potentially leading to memory corruption or crashes.

Technical details

The vulnerability exists in iceoryx2 versions greater than v0.8.0 where StaticString exposes its contents as mutable bytes through safe APIs. The String::as_str() method then converts these unvalidated bytes into a Rust string slice without confirming UTF-8 validity, allowing an attacker to create invalid &str references. This violates Rust's memory safety guarantees and enables undefined behavior through entirely safe code patterns.

Affected products

  • Eclipse iceoryx2 greater than v0.8.0

Timeline

  • 2026-09-21: disclosed

References