Glossaire
Définitions claires des termes de sûreté mémoire, d'exploitation et de mitigation utilisés dans les guides.
Les guides sont publiés d'abord en anglais. Les traductions suivront.
- AddressSanitizer (ASan)
- A compiler instrumentation and runtime that detects out-of-bounds accesses, use-after-free and double free at the exact faulting instruction.
- ASLR
- Address Space Layout Randomization: the operating system places the stack, heap, libraries and executable at random addresses on each run.
- Control-flow integrity (CFI)
- A family of mitigations that check at runtime that indirect calls, jumps and returns go only to targets the program could legitimately reach.
- Double free
- Freeing the same heap allocation twice, which corrupts allocator free lists and can lead to memory corruption (CWE-415).
- Format-string vulnerability
- A bug where untrusted input is passed as the format argument of printf-style functions, letting it read or write memory through conversion specifiers (CWE-134).
- Fuzzing
- Automated testing that feeds a program large numbers of generated inputs to find crashes; coverage-guided fuzzers evolve inputs that reach new code.
- Integer overflow
- An arithmetic result that exceeds the range of its integer type and wraps or triggers undefined behaviour, often producing undersized buffers (CWE-190).
- Memory safety
- The property that a program only accesses memory within the bounds and lifetime of valid objects, ruling out overflows, use-after-free and double free.
- NX bit (DEP)
- A page-level permission that marks memory as non-executable, so data written to the stack or heap cannot run as code. Known as DEP on Windows.
- PIE (position-independent executable)
- An executable compiled so it can run at any address, letting ASLR randomize the program's own code and data, not only its libraries.
- RELRO
- Relocation Read-Only: a linker and loader feature that makes the GOT and other relocation data read-only after startup, so they cannot be overwritten.
- Return-oriented programming (ROP)
- A code-reuse technique that chains short existing instruction sequences ending in return instructions, used to work around non-executable memory.
- Shadow stack
- A separate, protected stack that stores only return addresses, so a return is allowed only if it matches the address saved at call time.
- Stack canary
- A secret value placed between a function's local buffers and its saved return data, checked before the function returns to detect stack buffer overflows.
- Use-after-free
- A memory-safety bug where a program keeps using a pointer after the memory it points to has been freed, often leading to type confusion (CWE-416).