Intel

AIKIDO-2025-10662

foyer-storage is vulnerable to Use After Free

Use After Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 6, 2025

50

Medium Risk

This Affects:

Rustfoyer-storage
0.19.0 - 0.19.2
Fixed in 0.20.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a vulnerability known as a heap-use-after-free issue in the PsyncIoEngine. It arises from improper buffer handling during the cancellation of tasks in I/O operations, which can lead to memory corruption. An attacker could exploit this vulnerability by strategically canceling tasks to trigger the use-after-free condition, potentially resulting in arbitrary code execution or a denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

foyer-storage is vulnerable to Use After Free in versions 0.19.0 - 0.19.2.

How to fix this

Upgrade the foyer-storage library to the patch version.