RUSTSEC-2026-0156
Bad-free in `MetaCallException::new`
Details
`exception_struct` is a local stack variable, but the code passes its address to the C language as `&mut exception_struct as *mut _ as *mut c_void`. Then, the returned `MetaCallException` value is stored here: ```rust Ok(Self { exception_struct: Arc::new(exception_struct), value: exception_ptr, leak: false, }) ``` Because leak is false, the destructor will run later. But the original exception pointer points to Rust stack memory.
## Trigger
```rust #[test] fn exception_bad_free_safe_api() { let original = metacall::MetaCallException::new( "test", "test", "test", 1, );
drop(original); // AddressSanitizer: bad-free } ```
## Impact
Every time the `MetaCallException` is created, when it is dropped, it leads to a bad-free. This can be triggered through the safe public API `MetaCallException::new()`, with no `unsafe` required from the caller.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0No fixed version published yet for metacall. Pin to a known-safe version or switch to an alternative.