3 ms·
Has anyone in infosec ever seen the term "use after free" before LLMs? Or is this basically an acronym claude invented? I say this because I see claude use this
by Uptrenda 3mo ago
Has anyone in infosec ever seen the term "use after free" before LLMs? Or is this basically an acronym claude invented? I say this because I see claude use this term all the time like its common knowledge but in 15+ years in tech never seen it myself. I've seen all kinds of terms used to describe memory errors: memory corruption, heap corruption, stack corruption, whatever, just never this acronym.
- abofh 3mo ago[flagged]
- Uptrenda 3mo ago[flagged]
- abofh 3mo ago[flagged]
- Uptrenda 3mo ago[flagged]
- dang 3mo agoHey guys - please don't do tit for tat spats on HN. I know how it feels (believe me, I know how it feels down to such a level that any hypothetical offspring would also know how it feels), but it only makes everything worse. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- dang 3mo agoHey guys - please don't do tit for tat spats on HN. I know how it feels (believe me, I know how it feels down to such a level that any hypothetical offspring would also know how it feels), but it only makes everything worse. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- dang 3mo agoI understand the response (hence https://news.ycombinator.com/item?id=48887373 https://news.ycombinator.com/item?id=48887373) but please don't react by breaking the site guidelines yourself. That only makes things worse. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- LastTrain 3mo agoThere is an interesting episode of This American Life about how everyone, everyone, has weird gaps in their knowledge that eventually get filled in sometimes fun or humiliating ways. You have these too.
- defrost 3mo agoI can see that you're old and that I'm older, but I fail to see the justification for being snarky about that. Please don't sneer, including at the rest of the community. ~ https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- dang 3mo agoPlease don't be snarky or cross into putdowns or personal attack. We're all in (let's call it) the unlucky 10,000 about something. About most things actually. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- abofh 3mo agoTo an extent that's fair, but you do understand that "ive not heard of a vulnerability older than me" begs credulity? Especially with the fifteen years experience comment? I'm all for not being snarky (I'm not), but this was bait
- dang 3mo agoI can understand why it had that effect on you but these are effects it's necessary to resist. From https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html, for example: "Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith."
- paulv 3mo agoIt has been a known bug class for quite some time.
- michaellee8 3mo agoif you have spend any amount of time in low level c vulnerabilities you will have heard about it, it is a very common time on the low level/cybersec space.
- mdkotlik 3mo agoyes, it’s a very common term in infosec. I haven’t heard the “UAF” acronym before though
- smcameron 3mo agoI've heard of use after free, but I've only heard UAF to mean Ukraine Armed Forces.
- LPisGood 3mo agoYes, it was a common attack vector in binary exploitation. Heap based attack vector like use after free, double free, heap overflows, and others are pretty neat. They force you to learn a lot about how malloc works. There is a lot of cool work that went into making memory allocation work well; the different arenas, fast bins, chunk headers, etc. are super cool.
- mirashii 3mo agoThis is and has been a common term in any systems programming concept for decades. You can, for example, search CVEs and easily find some from over 15 years ago: https://www.cve.org/CVERecord?id=CVE-2010-1119 https://www.cve.org/CVERecord?id=CVE-2010-1119 It was even enumerated in the first pass of CWE as CWE-416 in 2006.
- Klonoar 3mo agoYou have somehow lived in a strange bubble. 2025: https://redis.io/blog/security-advisory-cve-2025-49844/ https://redis.io/blog/security-advisory-cve-2025-49844/ 2023: https://seclists.org/oss-sec/2023/q2/133 https://seclists.org/oss-sec/2023/q2/133 2022: https://www.zerodayinitiative.com/advisories/ZDI-22-1690/ https://www.zerodayinitiative.com/advisories/ZDI-22-1690/ 2014: https://ftp.openbsd.org/pub/OpenBSD/patches/5.4/common/008_openssl.patch https://ftp.openbsd.org/pub/OpenBSD/patches/5.4/common/008_o... It's an issue as old as time, or thereabouts.
- asveikau 3mo agoI haven't really seen it as an acronym "UAF", but I can't recall the first time I heard "use after free". It was probably in the previous century. The idea that Claude came up with it is ridiculous.
- atoav 3mo agoHuh? That is a really common term. There have been even memes about it. I remember roughly 5 years ago I first heard the ironic; "Real men use after free" in a discussion about Rust's benefits as its borrowing checker would have also prevented this one. "Use after free" is also described in most standard books about C as a thing you should never do, have you read one?
- hgoel 3mo agoI'm surprised that UAF as an acronym is apparently unusual even among people familiar with use-after-free as a concept. I thought that was a pretty typical acronym in the context of software.