---
id: RUSTSEC-2026-0302
title: '`stack-graphs` C API exports are safe `extern "C"` functions'
summary: '`stack-graphs` C API exports are safe `extern "C"` functions'
severity: none
vendor: stack-graphs
product: stack-graphs
ecosystem: rust
affected:
  - stack-graphs >= 0.0.3-0
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T21:00:02.879515742Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0302'
references:
  - url: 'https://crates.io/crates/stack-graphs'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0302.html'
  - url: 'https://github.com/rustsec/advisory-db/issues/3241'
  - url: 'https://github.com/github/stack-graphs'
tags:
  - osv
  - rust
ingestedAt: '2026-09-24T07:16:01.872Z'
---

## Overview

`stack_graphs::c` is a public module. From 0.0.3 through the current crates.io release 0.14.1, its pointer-taking entry points are `pub extern "C" fn` rather than `unsafe fn`. Safe Rust can call them.

`sg_stack_graph_free` frees the pointer with `Box::from_raw`. `sg_stack_graph_free(std::ptr::null_mut())` is immediate undefined behavior. The same shape is used by the other `*_free` exports and by getters and mutators that dereference the caller-supplied pointer or pass it to `from_raw_parts` (`sg_stack_graph_nodes`, `sg_stack_graph_add_edges`, and the rest of the pointer-taking functions in `src/c.rs`). Constructors that take no pointer are not part of this issue.

The upstream repository is archived, so a fix cannot be filed there and no patched release exists. The soundness fix is to make every pointer-taking export `unsafe extern "C" fn`, with a safety comment that the pointer is non-null and, for `free`, came from the matching constructor.

## Affected packages

- `stack-graphs >= 0.0.3-0`

## Remediation

Refer to the advisory for the patched release.
