
The episode discusses updates to the Pointer Ownership Model for C to address temporal memory safety issues in C and C++ programming.
In October 2025, CyberPress reported a critical security vulnerability in the Redis Server, an open-source in-memory database that allowed authenticated attackers to achieve remote code execution through a use-after-free flaw in the Lua scripting engine. In 2024, another prominent temporal memory safety flaw was found in the Netfilter subsystem in the Linux kernel: CVE-2024-1086 . Bugs related to temporal memory safety, such as use-after-free and double-free vulnerabilities, are challenging issues in C and C++ code. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI) , Lori Flynn , a senior software security research er in the SEI's CERT Division, and David Svoboda , a senior software engineer, also in CERT, sit down with Tim Chick , technical manager of CERT's Applied Systems Group, to discuss recent updates to the Pointer Ownership Model for C , a modeling framework designed to improve the ability of developers to statically analyze C programs for errors involving temporal memory.
Host: Tim Chick
Guests: Lori Flynn, David Svoboda
Organizations: Carnegie Mellon University Software Engineering Institute, Redis Server, Linux
Explore listener stats, chart rankings, contacts and more on the Software Engineering Institute (SEI) Podcast Series podcast page.