# Security Bug - Memory leak when calling a canister method via \`ic\_cdk::call\`

**URL:** <https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782>\
**Category:** Developers\
**Tags:** security, CDK\
**Created:** [September 5, 2024, 1:10pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782 "2024-09-05T13:10:07Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![vsekar](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Post date:** [September 5, 2024, 1:10pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/1 "2024-09-05T13:10:07Z")

</div>

## Dear all,

We recently discovered a memory leak in the `ic_cdk::call*` implementation in [@dfinity/cdk-rs](https://github.com/dfinity/cdk-rs). Canisters built in Rust with `ic_cdk` and `ic_cdk_timers` are affected. If these canisters call a canister method, use timers or heartbeat, they will likely leak a small amount of memory on every such operation. **In the worst case, this could lead to heap memory exhaustion triggered by an attacker.**

This is a high severity security issue and the patch has been backported to all minor versions between `>= 0.8.0, <= 0.15.0`. The patched versions available are `0.8.2, 0.9.3, 0.10.1, 0.11.6, 0.12.2, 0.13.5, 0.14.1, 0.15.1` and their previous versions have been yanked. Please see the [GitHub Security Advisory](https://github.com/dfinity/cdk-rs/security/advisories/GHSA-rwq6-crjg-9cpw) for more information.

We encourage the ICP community to report any new issues or bugs found responsibly. Please refer to the [Bug Bounty program](https://dfinity.org/bug-bounty/) for more information.

Please reach out to us in this thread or privately if you have any questions.

---

<div class="post-metadata">

**Author:** ![itowner](https://avatars.discourse-cdn.com/v4/letter/i/b2d939/32.png) [@itowner](https://forum.dfinity.org/u/itowner)\
**Post date:** [September 5, 2024, 1:25pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/2 "2024-09-05T13:25:28Z")

</div>



---

<div class="post-metadata">

**Author:** ![peterparker](https://avatars.discourse-cdn.com/v4/letter/p/b9bd4f/32.png) [@peterparker](https://forum.dfinity.org/u/peterparker)\
**Post date:** [September 7, 2024, 3:08pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/3 "2024-09-07T15:08:00Z")

</div>

Sharing for visibility: According to this post, the security advisory on crates might contain a typo regarding the safest latest version, listing v16.0.0 instead of v0.16.0

> [@RUSTSEC 2024-0372 ic-cdk not accepting 0.16.0](https://forum.dfinity.org/t/rustsec-2024-0372-ic-cdk-not-accepting-0-16-0/34844):
>
> shouldn’t this be 0.16.0?

---

<div class="post-metadata">

**Author:** ![vsekar](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Post date:** [September 7, 2024, 3:36pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/4 "2024-09-07T15:36:45Z")

</div>

my bad, too many versions. I have made a PR for the [fix](https://github.com/rustsec/advisory-db/pull/2073)

---

<div class="post-metadata">

**Author:** ![lastmjs](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/lastmjs/32/3406_2.png) [@lastmjs](https://forum.dfinity.org/u/lastmjs)\
**Post date:** [September 9, 2024, 3:31pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/5 "2024-09-09T15:31:36Z")

</div>

So…does ic-cdk-timers need to be updated? Or just ic-cdk? It’s confusing that both are listed by the advisory only mentions the ic-cdk crate.

---

<div class="post-metadata">

**Author:** ![vsekar](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Post date:** [September 10, 2024, 11:13am UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/6 "2024-09-10T11:13:00Z")

</div>

Updating `ic-cdk` should be enough since `ic-cdk-timers` pulls in `ic-cdk` as a dependency.

---

<div class="post-metadata">

**Author:** ![lastmjs](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/lastmjs/32/3406_2.png) [@lastmjs](https://forum.dfinity.org/u/lastmjs)\
**Post date:** [September 10, 2024, 8:29pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/7 "2024-09-10T20:29:31Z")

</div>

Azle 0.24.1 and Kybra 0.7.0 both have the fix, please upgrade if this vulnerability concerns you. All Azle and Kybra devs should upgrade if performing cross-canister calls on mainnet, as the leak seems highly likely to affect you over time.

---

<div class="post-metadata">

**Author:** ![robin-kunzler](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/robin-kunzler/32/3249_2.png) [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Post date:** [September 12, 2024, 7:59am UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/8 "2024-09-12T07:59:05Z")

</div>

@lastmjs Thanks so much for fixing Azle and Kybra so quickly! Is there an easy way to let the Azle or Kybra users know they should upgrade? For example, thanks to the GitHub and RUSTSEC advisories for cdk-rs, GitHub or `cargo audit` would bring up the issue automatically if a Rust project depends on the lib. But I’m not sure that would be the case if someone uses Azle or Kybra?

---

<div class="post-metadata">

**Author:** ![lastmjs](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/lastmjs/32/3406_2.png) [@lastmjs](https://forum.dfinity.org/u/lastmjs)\
**Post date:** [September 12, 2024, 1:59pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/9 "2024-09-12T13:59:32Z")

</div>

We mentioned it in the Discord channels and I let a couple devs know directly.

Azle could probably have this done through npm audit, but I haven’t ever submitted an advisory like this. Have you? I wonder if anyone can submit an advisory for a package on npm.

I’m not sure if PyPI has something like this.

Both projects are still in beta with a heavy exclaimer that specifically mentions security… though it does say unknown vulnerabilities, but I think the point gets across.

---

<div class="post-metadata">

**Author:** ![lastmjs](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/lastmjs/32/3406_2.png) [@lastmjs](https://forum.dfinity.org/u/lastmjs)\
**Post date:** [September 12, 2024, 2:03pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/10 "2024-09-12T14:03:17Z")

</div>

Actually, do you have the option of adding npm or PyPI packages to your security advisory? It seems like npm might pull from GitHub advisories.

---

<div class="post-metadata">

**Author:** ![vsekar](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Post date:** [September 24, 2024, 8:16am UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/11 "2024-09-24T08:16:05Z")

</div>

It can be added in the same advisory but I feel it would be cleaner if you can replicate the advisory in Azle / Kybra repository since the higher level APIs affected are different between the CDKs and you would also be able to add more context for the developers. You can also refer the same CVE in the advisory.

Just for my understanding, how does Azle / Kybra integrate with `ic_cdk` ? Do you have your own implementation over the system APIs or do you call into `ic_cdk` via FFI and linkers? If it’s the latter, we will make sure we will loop you in asap in the future if there is a new vulnerability.

---

<div class="post-metadata">

**Author:** ![lastmjs](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/lastmjs/32/3406_2.png) [@lastmjs](https://forum.dfinity.org/u/lastmjs)\
**Post date:** [September 27, 2024, 5:44pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782/12 "2024-09-27T17:44:36Z")

</div>

> [@vsekar](#):
>
> Just for my understanding, how does Azle / Kybra integrate with `ic_cdk` ? Do you have your own implementation over the system APIs or do you call into `ic_cdk` via FFI and linkers? If it’s the latter, we will make sure we will loop you in asap in the future if there is a new vulnerability.

We do not have our own implementation over the system APIs, we rely heavily on ic\_cdk and other DFINITY Rust crates
