Eclipse iceoryx2 <v0.8.0: StaticString Exposes Mutable Bytes, UBA
CVE-2026-92612 Published on September 21, 2026
In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Vulnerability Analysis
CVE-2026-92612 is exploitable with local system access. This vulnerability is consided to have a high level of attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-92612. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Exposed Dangerous Method or Function
The software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Affected Versions
Eclipse Foundation Eclipse iceoryx™:- Version 0.8.1, <= * is affected.