Fixed-size buffer overflow

Fixed-size buffer overflow

Description

Copying or reading more bytes into a fixed-size stack buffer than it can hold can overwrite adjacent stack memory.

Potential impact

  • Crashes, data corruption, or control-flow hijacking may result.

Remediation

Keep the length within the destination buffer's capacity and use wrappers that determine buffer sizes automatically.

Examples

Before

c
char buf[8];
memcpy(buf, src, 32);

After

c
char buf[8];
memcpy(buf, src, sizeof(buf));

Explanation:

  • Before: The code copies 32 bytes into an eight-byte buffer.
  • After: The destination array's size limits the copy length. This byte-copy example assumes that at least eight bytes can be read from src; it does not add a string terminator.

References