https://www.cisa.gov/news-events/alerts/2024/06/26/cisa-and-partners-release-guidance-exploring-memory-safety-critical-open-source-projects Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know Dot gov Official websites use .gov A .gov website belongs to an official government organization in the United States. HTTPS Secure .gov websites use HTTPS A lock (A locked padlock) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue CISA Logo Americas Cyber Defense Agency CISA Logo Search Menu America's Cyber Defense Agency Close * Topics Topics Cybersecurity Best Practices Cyber Threats and Advisories Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutives High-Risk Communities * Spotlight * Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups * News & Events News & Events News Events Cybersecurity Alerts & Advisories Directives Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! * Careers Careers Benefits & Perks HireVue Applicant Reasonable Accommodations Process Hiring Resume & Application Tips Students & Recent Graduates Veteran and Military Spouses Work @ CISA * About About Culture Divisions & Offices Regions Leadership Doing Business with CISA Site Links Reporting Employee and Contractor Misconduct CISA GitHub CISA Central 2023 Year In Review Contact Us Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue Breadcrumb 1. Home 2. News & Events 3. Cybersecurity Advisories 4. Alert Share: Alert CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects Release Date June 26, 2024 Today, CISA, in partnership with the Federal Bureau of Investigation, Australian Signals Directorate's Australian Cyber Security Centre, and Canadian Cyber Security Center, released Exploring Memory Safety in Critical Open Source Projects. This guidance was crafted to provide organizations with findings on the scale of memory safety risk in selected open source software (OSS). This joint guidance builds on the guide The Case for Memory Safe Roadmaps by providing a starting point for software manufacturers to create memory safe roadmaps, including plans to address memory safety in external dependencies which commonly include OSS. Exploring Memory Safety in Critical Open Source Projects also aligns with the 2023 National Cybersecurity Strategy and corresponding implementation plan, which discusses investing in memory safety and collaborating with the open source community--including the establishment of the interagency Open Source Software Security Initiative (OS3I) and investment in memory-safe programming languages. CISA encourages all organizations and software manufacturers to review the methodology and results found in the guidance to: * Reduce memory safety vulnerabilities; * Make secure and informed choices; * Understand the memory-unsafety risk in OSS; * Evaluate approaches to reducing this risk; and * Continue efforts to drive risk-reducing action by software manufacturers. To learn more about taking a top-down approach to developing secure products, visit CISA's Secure by Design webpage. This product is provided subject to this Notification and this Privacy & Use policy. Please share your thoughts We recently updated our anonymous product survey; we'd welcome your feedback. Related Advisories Jun 26, 2024 Alert CISA Adds Three Known Exploited Vulnerabilities to Catalog Jun 25, 2024 Alert CISA Releases Two Industrial Control Systems Advisories Jun 21, 2024 Alert Juniper Networks Releases Security Bulletin for Juniper Secure Analytics Jun 20, 2024 Alert CISA Releases Guidance on Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: (SMBs) Return to top * Topics * Spotlight * Resources & Tools * News & Events * Careers * About Cybersecurity & Infrastructure Security Agency * Facebook * Twitter * LinkedIn * YouTube * Instagram * RSS CISA Central 1-844-Say-CISA SayCISA@cisa.gov DHS Seal CISA.gov An official website of the U.S. Department of Homeland Security * About CISA * Budget and Performance * DHS.gov * Equal Opportunity & Accessibility * FOIA Requests * No FEAR Act * Office of Inspector General * Privacy Policy * Subscribe * The White House * USA.gov * Website Feedback