Aller au contenu

0x1000 · Domaine

Classes de vulnérabilités

Les bugs de sûreté mémoire se répartissent en un petit nombre de classes récurrentes. Chaque guide montre le motif vulnérable en quelques lignes de C, explique pourquoi il corrompt la mémoire, puis présente le correctif, l'avertissement du compilateur ou le sanitizer qui le détecte, et la mitigation qui en limite l'impact.

Guides de ce domaine

  1. Why writing past a stack buffer is dangerous, the C patterns that cause it, how compilers and sanitizers catch it, and the fixes and mitigations that contain it.

  2. How heap memory bugs corrupt allocator metadata and object state, why use-after-free is so dangerous, and the allocator hardening, sanitizers and ownership rules that stop them.

  3. How integer overflow, truncation and signedness errors turn into memory corruption, why user-controlled format strings are dangerous, and the checks and warnings that prevent both.

Les guides sont publiés d'abord en anglais. Les traductions suivront.

Autres domaines