Canonical security audit of rust-coreutils reveals 113 CVEs

Posted by nukem996@reddit | linux | View on Reddit | 152 comments

While it's great that Canonical did the audit and is working to fix these CVEs this shows that Rust isnt some magic language where CVEs dont happen.

It brings up the question, is a Rust rewrite worth it? These CVEs were not found in the C version coreutils and were only found due to a paid audit.