A better Windows kernel Rust bug

their belief that Rust out of bounds errors shouldn't bring down the system

I have seen many cases where people got surprised that Rust program's unexpected behaviors. I think we should add more explanation of these two very important chapters Behavior considered undefined and Behavior not considered unsafe in The Rust Reference, mapping those low-level details to high-level vulnerability descriptions that normal people can understand.

For example:

(all below are discussed in safe Rust context)

  • Rust program may abort and unwind
  • Rust program may contain RCE vulnerabilities caused by logic error
    • For example, command injection if the developer simply concat commands and throw it to /bin/sh to execute
    • For example, developers use arena to simulate a "heap", and use index to simulate the address. Then some wrong logic may lead to situations like heap overflow, double free or use-after-free.
  • Rust program can never contain RCE vulnerabilities caused by control-flow-hijack
    • For example, stack overflow to overwrite return address, or heap overflow to overwrite some function pointers.