Intel

AIKIDO-2026-635394

fragile is vulnerable to Use After Free

Use After Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

50

Medium Risk

This Affects:

RUSTfragile
1.2.0 - 2.1.0
Fixed in 3.0.0
Are you affected? Scan for Free

TL;DR

Sticky (from the fragile package) validates access by comparing the current thread's ID against the ID recorded at creation, then reads the matching entry straight out of a global thread local registry. The registry does not track whether a thread's storage has since been torn down and reinitialized, so a handle created before teardown can still read or drop an entry that now belongs to a different, replaced registry generation, producing a stale or dangling access. A panic raised while that teardown runs aborts the whole process instead of failing safely. The fix adds a registry generation check and a teardown aware thread ID lookup so stale entries are rejected instead of accessed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you apply the optional slab feature.

Background info

fragile is vulnerable to Use After Free in versions 1.2.0 - 2.1.0.

How to fix this

Upgrade the fragile library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform