4 ms·
> It would be interesting to study what percentage of security failures can be partly or entirely attributed to compiler "optimizations". I bet it's roughly no
by wolf550e 2y ago
> It would be interesting to study what percentage of security failures can be partly or entirely attributed to compiler "optimizations".
I bet it's roughly none.
- g-b-r 2y agoOh yeah, because no security failure was ever related to undefined behavior
- uecker 2y agoThis is a different question though. A lot of UB issues are related to out-of-bounds accesses and use-after-free. But those are problematic also without optimization. The cases where optimization introduce security issues are more subtle and less common. Signed overflow related issues come to mind, but there I think UB isnow part of the solution via sanitizers (and errors related to unsigned wraparound which is defined is the far more vexing problem) and similar for dereferencing null pointers which can also easily be catched by sanitizers.
- JonChesterfield 2y agoDeleting null pointer checks in the Linux kernel is the first one to come to mind
- wolf550e 2y agoThat's one CVE, right? How many other vulnerabilities were caused by compiler optimizations, whether they were bugs in the compiler or allowed by the spec?
- JonChesterfield 2y agoYou can probably enumerate them by searching for GCC compiler flags in the corresponding bug tracker. Start with ftrapv and fno-strict-aliasing. Those diverge-from-c flags exist to make code slower in exchange for not being broken.
- yencabulator 2y agoThe article links to an attack that extracts a 512-bit secret key in 5-10 minutes: https://pqshield.com/pqshield-plugs-timing-leaks-in-kyber-ml-kem-to-improve-pqc-implementation-maturity/ https://pqshield.com/pqshield-plugs-timing-leaks-in-kyber-ml... https://github.com/antoonpurnal/clangover https://github.com/antoonpurnal/clangover