C · 6 · Advanced / Job-Ready30 / 35 · 86%
Sanitizers, Valgrind & Secure C
The tools that turn silent UB into loud crashes — plus the classic security bugs.
shortcuts: ← prev · → next · M mark
1
AddressSanitizer
Catches heap-buffer-overflow, use-after-free, double-free.
Syntax
asan
gcc -fsanitize=address -g app.c -o app
./appOutput
==12345==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x... at pc 0x... WRITE of size 4 at 0x... thread T0
2
UBSan
Catches signed overflow, misaligned loads, shift-out-of-range.
Syntax
ubsan
gcc -fsanitize=undefined -g app.c -o app3
Buffer Overflow
The bug behind Morris, Heartbleed and thousands more.
Example
example
char name[16];
gets(name); // NEVER — deprecated, no bounds check
strcpy(name, argv[1]); // also unsafe if argv[1] is long
// SAFE:
fgets(name, sizeof name, stdin);
snprintf(name, sizeof name, "%s", argv[1]);4
Format-String Bug
%n and friends let an attacker read/write arbitrary memory.
Example
example
printf(user_input); // ATTACKER controls format string!
printf("%s", user_input); // safe