3 ms·
Wow, that paper is extremely wrong. > Memory deallocation can be modeled as an assignment. For example, the statement free(p) can be represented by the stateme
by roca 5y ago
Wow, that paper is extremely wrong.
> Memory deallocation can be modeled as an assignment. For example, the statement free(p) can be represented by the statement p=invalid, where invalid is a special untyped pointer to a temporally ‘invalid’ range of memory.
Absolutely not. That works for memory accesses through 'p'. It doesn't help you at all for memory accesses through other pointer aliases to the same memory block.
I mean, it's trivial to replace "free(p)" with a macro that also nulls out 'p', but no-one claims that that solves UAF bugs.
- naasking 5y agoYou can't quote a paragraph out of context and simply claim it's wrong. Whether their claim is wrong depends entirely on the global invariants their analysis ensures.
- roca 5y agoI skimmed the entire paper before making that comment. I'm pretty sure I understand it. BTW I have a PhD in static program analysis. If you think the paper is right, just explain how it detects use-after-free in the following code fragment: int* p = (int*)malloc(sizeof(int)); int* q = p; free(p); *q = 1;
- josephcsible 5y agoIt looks to me like the statement you quoted as being wrong is indeed wrong, but the technique in the paper is actually doing something different than that, and what it's actually doing does work. This was a clue to that: > After this assignment, the base and bound of p would be updated to be equal to that of the invalid pointer, and any pointer derived from or aliased with p would inherit this metadata as well (see Section 3.5). Looking at section 3.5, it sounds like what it's actually doing is keeping a global table of every valid base pointer and its maximum offset, and when you free a pointer, it updates that table accordingly, not just the local variable containing the pointer as it previously said.
- roca 5y agoThat wouldn't be crazy, and it's not much different to what ASAN does. But then what happens if/when a subsequent call to malloc() reuses that memory location? That location's entry in that global table is given a new maximum offset, and now the old pointer and the new pointer are both pointing to "valid" memory and you have memory corruption as they stomp on each other's data.