VDB
Sign up
—

RUSTSEC-2026-0139

Null-pointer dereference and double-free via safe APIs

Details

Two soundness violations exist in the Rust bindings for MetaCall:

**Null-pointer dereference:** `MetaCallFuture::new_raw()` accepts a raw pointer without validation. The `Debug` impl calls `Box::from_raw(self.data)` on it. Passing a null pointer causes the `Debug` impl to construct a `NonNull` from null, producing undefined behavior.

**Double-free:** `MetaCallPointer::clone()` shares the same `rust_value` raw pointer between the clone and the original. Calling `get_value_untyped()` on both clones calls `Box::from_raw` on the same pointer twice, resulting in a double-free.

Both issues can be triggered through safe public APIs — `MetaCallFuture::new_raw()`, `MetaCallPointer::new()`, `clone()`, and `get_value_untyped()` — with no `unsafe` required from the caller.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/metacall
Introduced in: 0.0.0-0

No fixed version published yet for metacall. Pin to a known-safe version or switch to an alternative.

References