Description
In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Published: 2026-09-21
Score: 1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Undefined Behavior via Safe API
Action: Assess Impact
AI Analysis

Impact

A bug in Eclipse iceoryx2’s StaticString implementation allows mutable raw bytes to be exposed through safe Rust APIs. The String::as_str() method converts these bytes into a UTF‑8 string slice without validating the encoding. An application can therefore create an invalid &str and trigger undefined behavior, potentially causing crashes or other unpredictable program behavior. The effect is limited to the process executing the vulnerable code and does not provide immediate remote code execution.

Affected Systems

Eclipse Foundation’s Eclipse iceoryx™ is affected in all versions of iceoryx2 greater than v0.8.0. The vulnerable code path exists in the StaticString library component and applies to releases prior to 0.10.0 as well as any later build that hasn’t applied the fix.

Risk and Exploitability

The CVSS score is 1, reflecting a low safety impact and no known exploit technique. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw results in undefined behavior rather than a direct code execution vector, the likelihood of exploitation is low and would require targeted local code modification. No public exploits or attack tools have been reported.

Generated by OpenCVE AI on September 21, 2026 at 12:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to iceoryx2 version 0.10.0 or newer, which removes the unsafe conversion path from StaticString.
  • If upgrading is not feasible, refactor the application to avoid using StaticString::as_str() when the data may not be valid UTF‑8, or replace it with a manual UTF‑8 validation routine before conversion.
  • As an interim workaround, patch or replace the vulnerable StaticString code with a custom wrapper that validates UTF‑8 or restricts exposure of raw bytes, ensuring that only valid UTF‑8 slices are created.

Generated by OpenCVE AI on September 21, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse iceoryx
Vendors & Products Eclipse
Eclipse iceoryx

Mon, 21 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Potential Undefined Behavior via Unsafe String Conversion in Eclipse iceoryx2’s StaticString

Mon, 21 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Weaknesses CWE-749
References
Metrics cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-21T11:09:34.304Z

Reserved: 2026-09-16T14:12:26.764Z

Link: CVE-2026-92612

cve-icon Vulnrichment

Updated: 2026-09-21T11:09:15.493Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T11:17:12.590

Modified: 2026-09-21T18:11:49.423

Link: CVE-2026-92612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:16Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function