A memory-corruption vulnerability in the Rust crate metacall allows a bad-free to be triggered through the safe public API MetaCallException::new(). The flaw affects crate version 0.5.10 and stems from passing the address of a stack-allocated Rust exception structure into C code, then later wrapping that pointer while the destructor still treats it as heap memory and frees it. RustSec assigned the issue RUSTSEC-2026-0156, warning that simply creating and dropping a MetaCallException can cause invalid memory deallocation without requiring callers to use unsafe Rust.
A related vulnerability report published in the metacall/core repository said AddressSanitizer reproduces the crash in exception_destroy and traced the root cause to storing a pointer to Rust stack memory while an internal leak flag remains false, causing Drop to free an invalid pointer. The same report flagged broader unsoundness in the crate, including shallow-copy Clone implementations over raw pointers and a safe new_raw API that accepts arbitrary raw pointers and dereferences C memory. No patched version was listed in the advisory, and the reporter recommended heap-allocating structures passed to C and marking raw-pointer constructors unsafe or otherwise restricting them.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
RustSec published advisory RUSTSEC-2026-0156 for a memory-corruption flaw in metacall involving a bad-free in MetaCallException::new. The advisory stated that creating and dropping a MetaCallException through the safe public API could trigger the flaw and listed no patched versions.
A vulnerability report disclosed multiple memory-safety issues in the Rust crate metacall, centered on a bad-free in MetaCallException::new and Drop affecting version 0.5.10. The report included a proof of concept, sanitizer-based reproduction steps, and analysis of related unsound APIs and pointer-handling flaws.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.