[ 
https://issues.apache.org/jira/browse/MAHOUT-2065?focusedWorklogId=221346&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-221346
 ]

ASF GitHub Bot logged work on MAHOUT-2065:
------------------------------------------

                Author: ASF GitHub Bot
            Created on: 01/Apr/19 16:32
            Start Date: 01/Apr/19 16:32
    Worklog Time Spent: 10m 
      Work Description: rawkintrevo commented on issue #370: MAHOUT-2065 [WIP] 
fix high risk crash bug
URL: https://github.com/apache/mahout/pull/370#issuecomment-478651302
 
 
   hey @bd2019us thanks.  We're in the middle of a code freeze at the moment, 
but also it appears that this is WIP (?).  Will review again after code freeze 
is done.
 
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
[email protected]


Issue Time Tracking
-------------------

    Worklog Id:     (was: 221346)
    Time Spent: 20m  (was: 10m)

> [SECURITY]newCachedThreadPool() has higher risk in causing OutOfMemoryError
> ---------------------------------------------------------------------------
>
>                 Key: MAHOUT-2065
>                 URL: https://issues.apache.org/jira/browse/MAHOUT-2065
>             Project: Mahout
>          Issue Type: Bug
>            Reporter: bd2019us
>            Priority: Major
>              Labels: pull-request-available
>         Attachments: 1.patch
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
>  Location : 
> community/mahout-mr/mr/src/main/java/org/apache/mahout/clustering/streaming/mapreduce/StreamingKMeansDriver.java:427
> Executors.newCachedThreadPool() is not secure when the number of threads is 
> not bounded, which can cause OutOfMemoryError and crash the program. For 
> security, using newFixedThreadPool(int) should be preferred, which can be 
> freely configured manually on demand.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to