their belief that Rust out of bounds errors shouldn't bring down the system
I have seen many cases where people got surprised that Rust program's unexpected behaviors. I think we should add more explanation of these two very important chapters Behavior considered undefined and Behavior not considered unsafe in The Rust Reference, mapping those low-level details to high-level vulnerability descriptions that normal people can understand.
For example:
(all below are discussed in safe Rust context)
- Rust program may abort and unwind
- Rust program may contain RCE vulnerabilities caused by logic error
- For example, command injection if the developer simply concat commands and throw it to
/bin/shto execute - For example, developers use arena to simulate a "heap", and use index to simulate the address. Then some wrong logic may lead to situations like heap overflow, double free or use-after-free.
- For example, command injection if the developer simply concat commands and throw it to
- Rust program can never contain RCE vulnerabilities caused by control-flow-hijack
- For example, stack overflow to overwrite return address, or heap overflow to overwrite some function pointers.