Skip to content

Glossary

Return-to-libc (ret2libc)

A code-reuse attack that redirects execution into an existing C library function, such as system(), instead of injecting new code.

Return-to-libc (ret2libc) is a return-oriented programming technique that defeats non-executable memory by returning into a function that already exists in the C library, most often system("/bin/sh"), rather than executing attacker-supplied code. Because the shared library is loaded at a randomized base under ASLR, the attacker usually first leaks a resolved library address to compute where system lives, then overwrites a saved return address to call it.

For defenders, ret2libc explains why PIE and information-leak hardening matter: without a leak, the library base is unknown, and without a writable saved return address the call never happens. A shadow stack detects the corrupted return. See the walkthrough on returning into libc.