A soundness flaw in the Rust cgmath crate allows Matrix2::swap_columns, Matrix3::swap_columns, and Matrix4::swap_columns to trigger undefined behavior from safe Rust code when callers pass identical column indices. The affected implementations in cgmath 0.18.0 use std::ptr::swap on two mutable references derived from the same matrix when inputs such as m.swap_columns(0, 0) are supplied, violating Rust aliasing guarantees and creating a memory-corruption risk.
The issue was documented in RustSec as RUSTSEC-2026-0197 and reproduced with proof-of-concept examples and Miri diagnostics showing a Stacked Borrows violation inside std::ptr::swap. No patched release was listed in the advisory, though the reported fix is straightforward: return early when both indices are equal before performing the swap, and apply that guard consistently across the Matrix2, Matrix3, and Matrix4 implementations.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub issue was opened against rustgd/cgmath reporting that cgmath 0.18.0's Matrix2/3/4 swap_columns implementations can trigger undefined behavior when called with identical indices. The report included proof-of-concept examples, noted Miri reports a Stacked Borrows violation in std::ptr::swap, and proposed returning early when a == b.
RustSec published advisory RUSTSEC-2026-0197 for the cgmath crate, describing a soundness issue in Matrix2::swap_columns, Matrix3::swap_columns, and Matrix4::swap_columns where identical indices can trigger undefined behavior from safe Rust code. The advisory states no patched version is available and notes a minimal remediation would be to return early when both indices are equal.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcerustsec.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.