| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This document outlines the security model for the Rust implementation of Apache Arrow (arrow-rs) and how to report vulnerabilities.
The arrow-rs project follows the Apache Arrow Security Model. In particular:
This implementation provides APIs such as ArrayData::validate_full to validate that Arrow data conforms to the specification.
Unexpected behavior (e.g., panics, crashes, or infinite loops) triggered by malformed input is generally considered a bug, not a security vulnerability, unless it is exploitable and could allow an attacker to
If that exploitation path is unclear, the issue should likely be reported as a bug.
Rust has a very specific definition of unsafe. When unsafe behavior results from using safe code, the code is unsound and can lead to undefined behavior (UB), which may be exploitable.
However, not all soundness issues are exploitable. In general, issues that result in undefined behavior using safe APIs are considered bugs unless they meet the exploitability bar defined above.
We therefore avoid classifying all unsoundness bugs as security vulnerabilities (e.g. filing RUSTSEC and/or CVE advisories), which helps avoid unnecessary downstream churn and keeps our focus on the most critical issues.
We treat all bugs seriously and welcome help fixing them. If you find a bug that does not meet the criteria for a security vulnerability, please report it in the public issue tracker.
For security vulnerabilities, please follow the responsible disclosure process below so we can investigate and fix the issue before it is exploited in the wild.
Do not file a public issue. Follow the ASF security reporting process by emailing security@apache.org.
Include in your report:
| Back | FazBrowse Home | New Git URL |