CISA urges use of memory safe code in software development

General News

Summary

The White House Office of the National Cyber Director in August issued a request for information on open source security, which sought input on the development of memory safe languages. Bob Lord, senior technical advisor at CISA, urged software developers to make the elimination of memory safety vulnerabilities from product lines a goal at their companies, in a blogpost released Wednesday. “Memory unsafety has plagued the software industry for decades and will continue to be a major source of vulnerabilities and real-world harm until top business leaders from the software manufacturers make appropriate investments and take ownership of the security outcomes of their customers,” Lord wote in the blog. Memory safety issues account for upwards of 70% of security vulnerabilities found in software, according to estimates by Google. Brian Fox, CTO and co-founder of Sonatype, said issues like null pointers and buffer overflows, which are symptoms of unsafe memory usage, account for a significant percentage of vulnerabilities.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies