{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,10,8]],"date-time":"2026-10-08T11:33:34Z","timestamp":1791459214243,"version":"4.3.4"},"reference-count":38,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,9,28]],"date-time":"2021-09-28T00:00:00Z","timestamp":1632787200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"China Education and Research Network","award":["NGII20190410"],"award-info":[{"award-number":["NGII20190410"]}]},{"name":"Research Grants Council of the Hong Kong Special Administrative Region, China","award":["CUHK 14210717"],"award-info":[{"award-number":["CUHK 14210717"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2022,1,31]]},"abstract":"<jats:p>Rust is an emerging programming language that aims at preventing memory-safety bugs without sacrificing much efficiency. The claimed property is very attractive to developers, and many projects start using the language. However, can Rust achieve the memory-safety promise? This article studies the question by surveying 186 real-world bug reports collected from several origins, which contain all existing Rust common vulnerability and exposures (CVEs) of memory-safety issues by 2020-12-31. We manually analyze each bug and extract their culprit patterns. Our analysis result shows that Rust can keep its promise that all memory-safety bugs require unsafe code, and many memory-safety bugs in our dataset are mild soundness issues that only leave a possibility to write memory-safety bugs without unsafe code. Furthermore, we summarize three typical categories of memory-safety bugs, including automatic memory reclaim, unsound function, and unsound generic or trait. While automatic memory claim bugs are related to the side effect of Rust newly-adopted ownership-based resource management scheme, unsound function reveals the essential challenge of Rust development for avoiding unsound code, and unsound generic or trait intensifies the risk of introducing unsoundness. Based on these findings, we propose two promising directions toward improving the security of Rust development, including several best practices of using specific APIs and methods to detect particular bugs involving unsafe code. Our work intends to raise more discussions regarding the memory-safety issues of Rust and facilitate the maturity of the language.<\/jats:p>","DOI":"10.1145\/3466642","type":"journal-article","created":{"date-parts":[[2021,9,28]],"date-time":"2021-09-28T16:49:24Z","timestamp":1632847764000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":66,"title":["Memory-Safety Challenge Considered Solved? An In-Depth Study with All Rust CVEs"],"prefix":"10.1145","volume":"31","author":[{"given":"Hui","family":"Xu","sequence":"first","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhuangbin","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of CSE, The Chinese University of Hong Kong, Shatin, N.T., China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingshen","family":"Sun","sequence":"additional","affiliation":[{"name":"Baidu Security, Sunnyvale, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yangfan","family":"Zhou","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University and Shanghai Key Laboratoryof Intelligent Information Processing, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael R.","family":"Lyu","sequence":"additional","affiliation":[{"name":"Department of CSE, The Chinese University of Hong Kong, Shatin, N.T., China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,9,28]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176330"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2889229"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428204"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360573"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01090-4_32"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the International Symposium on Formal Methods for Components and Objects. Springer, 200\u2013225","author":"Benveniste Albert","year":"2007","unstructured":"Albert Benveniste , Beno\u00eet Caillaud , Alberto Ferrari , Leonardo Mangeruca , Roberto Passerone , and Christos Sofronis . 2007 . Multiple viewpoint contract-based specification and design . In Proceedings of the International Symposium on Formal Methods for Components and Objects. Springer, 200\u2013225 . Albert Benveniste, Beno\u00eet Caillaud, Alberto Ferrari, Leonardo Mangeruca, Roberto Passerone, and Christos Sofronis. 2007. Multiple viewpoint contract-based specification and design. In Proceedings of the International Symposium on Formal Methods for Components and Objects. Springer, 200\u2013225."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/234528.234740"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Mohan Cui Chengjun Chen Hui Xu and Yangfan Zhou. 2021. SafeDrop: Detecting memory deallocation bugs of rust programs via static data-flow analysis. arXiv:2103.15420 Retrieved from https:\/\/arxiv.org\/abs\/2103.15420.  Mohan Cui Chengjun Chen Hui Xu and Yangfan Zhou. 2021. SafeDrop: Detecting memory deallocation bugs of rust programs via static data-flow analysis. arXiv:2103.15420 Retrieved from https:\/\/arxiv.org\/abs\/2103.15420.","DOI":"10.1145\/3542948"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/3291168.3291176"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3371102"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714635"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2015.65"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277212"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380413"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/3195638.3195686"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/PDCAT.2011.18"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678813"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3158154"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3144555.3144562"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818302.2818306"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131672.3136988"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/INDIN.2018.8471992"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380325"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.23919\/MIPRO.2019.8756695"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2018.00028"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1002\/(SICI)1096-9942(199901\/03)5:1<35::AID-TAPO4>3.0.CO;2-4"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3386036"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2103656.2103718"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0002-9947-1953-0053041-6"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1101815.1101818"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/644760.644766"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2015.28"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2004.5"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277262"},{"key":"e_1_2_1_39_1","unstructured":"Zeming Yu Linhai Song and Yiying Zhang. 2019. Fearless concurrency? understanding concurrent programming safety in real-world rust software. arXiv:1902.01906 Retrieved from https:\/\/arxiv.org\/abs\/1902.01906.  Zeming Yu Linhai Song and Yiying Zhang. 2019. Fearless concurrency? understanding concurrent programming safety in real-world rust software. arXiv:1902.01906 Retrieved from https:\/\/arxiv.org\/abs\/1902.01906."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3466642","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3466642","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:24:52Z","timestamp":1750181092000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3466642"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,28]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,1,31]]}},"alternative-id":["10.1145\/3466642"],"URL":"https:\/\/doi.org\/10.1145\/3466642","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,28]]},"assertion":[{"value":"2020-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}