Learning path

Full curriculum

Full curriculum

Unit content

Memory-safety vulnerabilities

A program is memory safe when it cannot access memory outside the objects and lifetimes permitted by its language and runtime model.

Memory-safety failures include

  • out-of-bounds reads and writes;
  • use-after-free and dangling-pointer access;
  • double free or invalid deallocation;
  • interpreting memory through invalid object assumptions.

These are more serious than ordinary incorrect results because memory often contains data and control state belonging to other parts of the process.

An out-of-bounds read can disclose secrets. An out-of-bounds write or use-after-free can corrupt data structures and, under favorable conditions for an attacker, influence later control flow.

Memory-safe languages prevent broad classes of these accesses through bounds checks, ownership rules, garbage collection or other enforcement. Unsafe languages and unsafe interfaces instead require the programmer and surrounding runtime to maintain the relevant invariants correctly.

Memory safety does not imply complete security, but violating it can destroy boundaries that higher-level code assumes are reliable.