C++ Logo

std-proposals

Advanced search

Re: [std-proposals] Draft 2: Error on out-of-bounds index

From: Thiago Macieira <thiago_at_[hidden]>
Date: Sat, 30 Aug 2025 09:29:16 -0700
On Friday, 29 August 2025 18:23:20 Pacific Daylight Time Oliver Hunt via Std-
Proposals wrote:
> Yes - and if you used a std::array, or a std::span, or a std::vector, or
> many other types - with the hardened runtime option, sigh - it would
> correctly fail without a security vulnerability.

I'd argue that a denial-of-service by causing the hardened checkers to trip
and halt the application is also a security vulnerability.

-- 
Thiago Macieira - thiago (AT) macieira.info - thiago (AT) kde.org
  Principal Engineer - Intel Platform & System Engineering

Received on 2025-08-30 16:29:20