5 ms·
Obviously the way to prevent this is by bounds checking, which is literally in the `770594e` patch. It's just a bug and they happen routinely in all languages.
by dvt 5mo ago
Obviously the way to prevent this is by bounds checking, which is literally in the `770594e` patch. It's just a bug and they happen routinely in all languages. Since this is doing pointer arithmetic, it could just as easily happen in unsafe Rust, for example.
- deleted 5mo ago[deleted]
- gpm 5mo agoLike they said, "no way to prevent this" (kind of bug from happening again).
- mikestorrent 5mo agoStatic analysis and other tools can find this, but they're expensive; wonder what the kernel team has access to?
- ivan_gammel 5mo agoTechnically, the kernel team is sufficiently competent to design and build bespoke tools for themselves. It‘s probably a question of risk assessment and priorities.
- PlasmaPower 5mo agoIf static analysis could actually find these issues with a reasonable false positive rate, the companies behind them would be running them on Linux to get the publicity of having found the issues like all the AI companies are doing now. Imo the good static analysis heuristics are already built into compilers or in open source linters.
- canucker2016 5mo agoThe cheap, low-hanging "fruit" lint rules have been added to today's C/C++ compilers. But these rules can be fragile, depending on what level the static analysis scan occurs - source-code-level-textual pattern matching or use of an AST/parse tree. Possible problems within a function should be discoverable. This particular bug would be hard to discover for a typical linter unless they knew/remembered that there are two execution paths for cleanup of a given element.
- deleted 5mo ago[deleted]
- TheAdamist 5mo agoIf not static analysis what would ai tools be considered? They're operating off the same source code Also nice the onion reference by op.
- PlasmaPower 5mo ago"static analysis" is usually deterministic rules you can e.g. put in CI. AI is also somewhat dynamic in that it can execute commands to try stuff out. The best AI vuln finding harnesses work that way, by essentially putting the AI inside of a fuzzer-like environment and telling it to produce a crash.
- wizzwizz4 5mo agoIt's a reference to Xe Iaso's blog (e.g. https://xeiaso.net/shitposts/no-way-to-prevent-this/CVE-2025-62229/ https://xeiaso.net/shitposts/no-way-to-prevent-this/CVE-2025...), which is itself a reference to The Onion.
- saghm 5mo agoIt's possible I had seen that blog post and not remembered! I was intending to reference the Onion though (and even googled to make sure I had the wording right), but seeing someone else make the same joke and forgetting is certainly something I would do
- canucker2016 5mo agoCoverity scans several open source projects for free. see https://scan.coverity.com/faq https://scan.coverity.com/faq and https://scan.coverity.com/projects https://scan.coverity.com/projects see https://scan.coverity.com/projects/linux https://scan.coverity.com/projects/linux for the linux-specific scan results - you need to create an account to view the reported defects. This past couple of weeks isn't a good look for them with the releases of defects found in Linux and Firefox.
- emmelaich 5mo agoLinus himself wrote a static analyzer. https://en.wikipedia.org/wiki/Sparse https://en.wikipedia.org/wiki/Sparse There are other free ones, I don't know if they're run as a matter of course.
- Rygian 5mo agoThat's not prevention. That's remediation.
- amluto 5mo agoBut one would have to explicitly choose to use unsafe Rust for this instead of ordinary safe Rust. And safe Rust has no particular difficulty writing to slots in an array or slice or vector specified by their index.
- skullone 5mo agoexcept nearly everyone uses unsafe rust
- Jtsummers 5mo ago> except nearly everyone uses unsafe rust Really? Why? I've not used Rust outside of some fairly small efforts, but I've never found a reason to reach for unsafe. So why is "nearly everyone" else using it?
- dvt 5mo agoLet's say you want to call win32 (or Mac) OS functions, all of a sudden you're doing all kinds of wonky pointer stuff because that's how these operating systems have been architected. Doing unsafe stuff is pretty inevitable if you want to do anything non-hello-world-ish.
- amluto 5mo agoSo what? Just because you used the keyword `unsafe` to call an unsafe API does not mean that you are going to use unsafe pointer access to write to a vector.
- Jtsummers 5mo ago> Doing unsafe stuff is pretty inevitable if you want to do anything non-hello-world-ish. So the vast majority of Rust projects involve writing at least one unsafe block? Is that really your claim?
- greiskul 5mo ago
- ellieh 5mo agosure, but with unsafe Rust you have a very clear marking for the section of code that requires additional care and attention. it is also customary to include a "SAFETY" comment outlining why using unsafe is OK here
- dvt 5mo agoYou actually kind of don't, I use like a zillion crates which have unsafe Rust in them and it's not like I'm sitting here reading every single line of their code. I like Rust for various reasons, but its memory safety is (imo) overstated, especially when doing low-level stuff.
- josephg 5mo agoAlmost all rust (95%) is safe rust. You can opt out of array bounds checks with unsafe { array.get_unchecked(idx) } instead of just typing array[idx]. But I can't remember the last time I saw anyone actually do that in the wild. Its not common practice, even in most low level code. Rust is bounds checked by default. C is not. Defaults matter because, without a convincing reason, most people program in the default way.
- deleted 5mo ago[deleted]
- sieabahlpark 5mo ago[dead]