Impact
A bug in Eclipse iceoryx2’s StaticString implementation allows mutable raw bytes to be exposed through safe Rust APIs. The String::as_str() method converts these bytes into a UTF‑8 string slice without validating the encoding. An application can therefore create an invalid &str and trigger undefined behavior, potentially causing crashes or other unpredictable program behavior. The effect is limited to the process executing the vulnerable code and does not provide immediate remote code execution.
Affected Systems
Eclipse Foundation’s Eclipse iceoryx™ is affected in all versions of iceoryx2 greater than v0.8.0. The vulnerable code path exists in the StaticString library component and applies to releases prior to 0.10.0 as well as any later build that hasn’t applied the fix.
Risk and Exploitability
The CVSS score is 1, reflecting a low safety impact and no known exploit technique. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw results in undefined behavior rather than a direct code execution vector, the likelihood of exploitation is low and would require targeted local code modification. No public exploits or attack tools have been reported.
OpenCVE Enrichment