lidavidm commented on issue #1234:
URL: https://github.com/apache/arrow-java/issues/1234#issuecomment-5010846352

   @zhangkre if you have vulnerabilities to disclose, please follow the ASF 
process: https://github.com/apache/arrow-java?tab=security-ov-file
   
   That said, we've been discussing the security policy for Arrow: 
https://arrow.apache.org/docs/format/Security.html 
   
   It's not clear to me that we'd consider memory leaks as vulnerabilities, 
unless it can be shown that an attacker can cause excessive memory usage with a 
very small or trivial input. Given that the IPC format allows (de)compression, 
unbounded memory usage is always possible and is something that should be 
mitigated in other ways, e.g. bounding the allocator and tying it to a health 
check on a service (although we should absolutely fix cases like these where 
possible and document this more clearly). 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to