CC Explainer
C · 6 · Advanced / Job-Ready30 / 35 · 86%

Sanitizers, Valgrind & Secure C

The tools that turn silent UB into loud crashes — plus the classic security bugs.

shortcuts: ← prev · → next · M mark
1

AddressSanitizer

Catches heap-buffer-overflow, use-after-free, double-free.

Syntax
asan
gcc -fsanitize=address -g app.c -o app
./app
Output
==12345==ERROR: AddressSanitizer:
   heap-buffer-overflow on address 0x... at pc 0x...
   WRITE of size 4 at 0x... thread T0
2

UBSan

Catches signed overflow, misaligned loads, shift-out-of-range.

Syntax
ubsan
gcc -fsanitize=undefined -g app.c -o app
3

Buffer Overflow

The bug behind Morris, Heartbleed and thousands more.

Example
example
char name[16];
gets(name);           // NEVER — deprecated, no bounds check
strcpy(name, argv[1]); // also unsafe if argv[1] is long

// SAFE:
fgets(name, sizeof name, stdin);
snprintf(name, sizeof name, "%s", argv[1]);
4

Format-String Bug

%n and friends let an attacker read/write arbitrary memory.

Example
example
printf(user_input);        // ATTACKER controls format string!
printf("%s", user_input);  // safe