Google is promoting safe memory handling tools in open source software

Google has initiated efforts to address issues in open source software caused by unsafe memory handling. According to Google, 70% of security issues in Chromium are due to memory handling errors, such as accessing a buffer after its associated memory has been freed (use-after-free). A study by Microsoft also concluded that 70% of all vulnerabilities patched in the reviewed software updates are due to unsafe memory handling. Another study showed that 53 out of 95 vulnerabilities identified in the curl utility could have been avoided if the code had been written in a language that ensures safe memory handling.

Examples of the initial initiatives financed by Google and conducted in collaboration with the ISRG (Internet Security Research Group) include the creation of an alternative HTTP backend for the curl utility and the development of a new TLS module for the Apache HTTP server. Both projects are implemented in Rust, a language focused on safe memory handling, which provides automatic memory management that, when used correctly (avoiding unsafe pointer operations), protects against issues like accessing memory after it has been freed, dereferencing null pointers, and buffer overflows.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster