Skip to content

Glossary

Plain-language definitions of the memory-safety, exploitation and mitigation terms used across the guides.

AddressSanitizer (ASan)
A compiler instrumentation and runtime that detects out-of-bounds accesses, use-after-free and double free at the exact faulting instruction.
ASLR
Address Space Layout Randomization: the operating system places the stack, heap, libraries and executable at random addresses on each run.
Control-flow integrity (CFI)
A family of mitigations that check at runtime that indirect calls, jumps and returns go only to targets the program could legitimately reach.
Double free
Freeing the same heap allocation twice, which corrupts allocator free lists and can lead to memory corruption (CWE-415).
Format-string vulnerability
A bug where untrusted input is passed as the format argument of printf-style functions, letting it read or write memory through conversion specifiers (CWE-134).
Fuzzing
Automated testing that feeds a program large numbers of generated inputs to find crashes; coverage-guided fuzzers evolve inputs that reach new code.
Integer overflow
An arithmetic result that exceeds the range of its integer type and wraps or triggers undefined behaviour, often producing undersized buffers (CWE-190).
Memory safety
The property that a program only accesses memory within the bounds and lifetime of valid objects, ruling out overflows, use-after-free and double free.
NX bit (DEP)
A page-level permission that marks memory as non-executable, so data written to the stack or heap cannot run as code. Known as DEP on Windows.
PIE (position-independent executable)
An executable compiled so it can run at any address, letting ASLR randomize the program's own code and data, not only its libraries.
RELRO
Relocation Read-Only: a linker and loader feature that makes the GOT and other relocation data read-only after startup, so they cannot be overwritten.
Return-oriented programming (ROP)
A code-reuse technique that chains short existing instruction sequences ending in return instructions, used to work around non-executable memory.
Shadow stack
A separate, protected stack that stores only return addresses, so a return is allowed only if it matches the address saved at call time.
Stack canary
A secret value placed between a function's local buffers and its saved return data, checked before the function returns to detect stack buffer overflows.
Use-after-free
A memory-safety bug where a program keeps using a pointer after the memory it points to has been freed, often leading to type confusion (CWE-416).