Description
Copying or reading more bytes into a fixed-size stack buffer than it can hold can overwrite adjacent stack memory.
Potential impact
- Crashes, data corruption, or control-flow hijacking may result.
Remediation
Keep the length within the destination buffer's capacity and use wrappers that determine buffer sizes automatically.
Examples
Before
c
char buf[8];
memcpy(buf, src, 32);
After
c
char buf[8];
memcpy(buf, src, sizeof(buf));
Explanation:
- Before: The code copies 32 bytes into an eight-byte buffer.
- After: The destination array's size limits the copy length. This byte-copy example assumes that at least eight bytes can be read from
src; it does not add a string terminator.