Executive brief
Salsa is a Rust library for incremental computation that caches query results. A use-after-free vulnerability in interned values can allow attackers to read arbitrary process memory or execute code through applications using vulnerable versions. The flaw triggers when dependency tracking bugs or incorrect equality checks cause stale cached results to be reused, then freed while still in use via safe Rust APIs.
Technical details
The vulnerability occurs in Salsa 0.23.0 through 0.28.4 when an interned value is used to access a tracked function's cached result without validating the reusable storage for the current database revision. While field reads were partially protected by debug_assert!, cached result access was unprotected. Bugs in dependency tracking or faulty Eq implementations can cause stale cached results containing freed interned values to be returned, leading to use-after-free through safe APIs. The fix adds assertions before returning references to ensure storage validity, preventing the unsafe state from being reached.
Affected products
- Salsa 0.23.0 to 0.28.4
Timeline
- 2026-09-24: disclosed