37
submitted 4 months ago by Occhioverde@feddit.it to c/rust@lemmy.ml
top 2 comments
sorted by: hot top controversial new old
[-] pineapple@lemmy.ml 2 points 3 months ago

Are memory errors in C and C++ the reason for the majority of modern security vulnerabilities?

[-] Ephera@lemmy.ml 1 points 1 week ago

Just ran across this post and your comment by chance, but well, yes:

The importance of memory safety cannot be overstated: a 2019 study estimated that 66% of Common Vulnerabilities and Exposures (CVEs) for iOS 12 and 71% of CVEs for Mojave were caused by memory safety issues. [...] a Google Project Zero review of exploits detected in-the-wild estimates that 75% of CVEs used in those exploits were memory safety vulnerabilities. Out of the 58 in-the-wild zero-days discovered in 2021, 67% were memory safety vulnerabilities.

Source: https://media.defense.gov/2025/Jun/23/2003742198/-1/-1/0/CSI_MEMORY_SAFE_LANGUAGES_REDUCING_VULNERABILITIES_IN_MODERN_SOFTWARE_DEVELOPMENT.PDF

this post was submitted on 21 May 2025
37 points (97.4% liked)

Rust Programming

8979 readers
1 users here now

founded 6 years ago
MODERATORS