{"id":"RUSTSEC-2026-0302","title":"`stack-graphs` C API exports are safe `extern \"C\"` functions","summary":"`stack-graphs` C API exports are safe `extern \"C\"` functions","severity":"none","vendor":"stack-graphs","product":"stack-graphs","ecosystem":"rust","affected":["stack-graphs >= 0.0.3-0"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T21:00:02.879515742Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0302","references":[{"url":"https://crates.io/crates/stack-graphs"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0302.html"},{"url":"https://github.com/rustsec/advisory-db/issues/3241"},{"url":"https://github.com/github/stack-graphs"}],"tags":["osv","rust"],"ingestedAt":"2026-09-24T07:16:01.872Z","slug":"RUSTSEC-2026-0302","body":"## Overview\n\n`stack_graphs::c` is a public module. From 0.0.3 through the current crates.io release 0.14.1, its pointer-taking entry points are `pub extern \"C\" fn` rather than `unsafe fn`. Safe Rust can call them.\n\n`sg_stack_graph_free` frees the pointer with `Box::from_raw`. `sg_stack_graph_free(std::ptr::null_mut())` is immediate undefined behavior. The same shape is used by the other `*_free` exports and by getters and mutators that dereference the caller-supplied pointer or pass it to `from_raw_parts` (`sg_stack_graph_nodes`, `sg_stack_graph_add_edges`, and the rest of the pointer-taking functions in `src/c.rs`). Constructors that take no pointer are not part of this issue.\n\nThe upstream repository is archived, so a fix cannot be filed there and no patched release exists. The soundness fix is to make every pointer-taking export `unsafe extern \"C\" fn`, with a safety comment that the pointer is non-null and, for `free`, came from the matching constructor.\n\n## Affected packages\n\n- `stack-graphs >= 0.0.3-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}