Martin Uecker, a biomedical engineering professor and Linux developer, discussed undefined behavior in C at Kernel Recipes, arguing that while C remains a valuable language for its portability and performance, its historical complexity and loose semantics around undefined behavior create ambiguity about expected program behavior and security implications.
Martin Uecker, a biomedical engineering professor and Linux user, discussed undefined behavior in C at Kernel Recipes, exploring whether C can become memory-safe. Despite C's portability, stability, and performance advantages, its historical complexity and the compiler freedom granted by undefined behavior semantics create challenges and disagreements about expected program behavior.
Google used Gemini AI and differential fuzzing to automatically convert giflib, a 3,000-line C image-processing library, into memory-safe Rust while maintaining ABI compatibility and runtime performance. The Rust version neutralized an unpatched heap write zero-day (CVE-2026-26740) before public disclosure and passed validation across 30 million real-world GIF assets and 200 million fuzzing iterations.
This technical article explains Rust's reborrowing mechanism, which allows mutable references to be passed to helper methods without consuming the original reference. Reborrowing creates temporary sub-borrows with shorter lifetimes, enabling practical use of mutable references while maintaining strict exclusivity. The compiler automatically handles this, similar to variable shadowing, by suspending the parent borrow during the child borrow's lifetime.
This post discusses Futhark's type system feature for in-place updates, which allows efficient array modifications by reusing memory while maintaining safety through aliasing tracking. The author explains how the type checker must reason about object identity and aliases to prevent consumed values from being referenced, and describes the complexity that arises when this interacts with other language features.
libfyaml v1.0.0-beta2 is a correctness and portability release fixing memory leaks, double frees, and other issues found through fuzzing, while adding support for multiple platforms including FreeBSD, NetBSD, OpenBSD, and various Linux architectures. The release introduces allocation failure injection testing and expands CI coverage across supported platforms.
A comprehensive empirical study evaluates automated C-to-Rust refactoring tools (C2Rust-analyze, CROWN, C2SaferRust, FLOURINE) on 116 C programs with memory security bugs. Results show that while these tools reduce unsafe Rust code, they fail to reliably eliminate memory security vulnerabilities: 342 programs fail compilation, 177 inherit original C bugs, and 77 introduce new Rust bugs.
Microsoft Edge's security team replaced the C implementation of Brotli compression in its network stack with a Rust implementation to improve memory safety. Brotli was chosen as the next rustification target because it processes untrusted network data at a critical point in the browser, has a mature Rust crate with production adoption, and is widely deployed on the modern web.
CobaltC is an AI-designed statically typed systems programming language with explicit ownership, memory safety, and compiler-checked borrowing. The project now includes both an interpreter (coby) and a native compiler (cobc) for x86_64 Linux, along with comprehensive documentation and example programs.
Researchers have developed Einstein, an automated tool that generates data-only attacks—exploits that corrupt a program's data rather than hijacking control flow. Published at USENIX Security 2024, the work challenges the assumption that such attacks are too complex to be practical, demonstrating that memory safety bugs (70% of security issues at major vendors) can be weaponized through malicious data manipulation.