Glossary
Stack canary
A secret value placed between a function's local buffers and its saved return data, checked before the function returns to detect stack buffer overflows.
A stack canary (also called a stack cookie or stack protector) is a random value the compiler writes into a function's stack frame, between local arrays and the saved frame pointer and return address. Before the function returns, the epilogue compares the value with the original, stored in thread-local storage. If a linear overflow of a local buffer has changed it, the program aborts with *** stack smashing detected *** instead of returning to a corrupted address.
GCC and Clang enable it with -fstack-protector-strong; MSVC uses /GS. On glibc the canary's lowest byte is zero, which stops string functions from copying it. Canaries do not protect other local variables or non-linear writes. See binary hardening flags.