Unit content
Memory-corruption exploit mitigations
Operating systems, compilers and runtimes can make memory-corruption vulnerabilities harder to exploit even when the underlying bug still exists.
Common mitigations include:
- non-executable data memory: writable pages such as stacks and heaps are not normally executable;
- address-space layout randomization (ASLR): code and data regions are placed at less predictable virtual addresses;
- stack canaries: selected stack frames contain a guard value checked before returning, detecting some overwrites;
- guard pages and hardened allocators: invalid accesses or suspicious heap patterns are made easier to detect.
These mechanisms break assumptions that many exploits rely on. They do not repair the original out-of-bounds access or use-after-free.
Mitigations also compose imperfectly. An information leak may reveal randomized addresses, and a corruption that avoids a canary can bypass that particular check.
The strongest fix is to remove or prevent the memory-safety violation; exploit mitigations provide defense in depth when prevention is incomplete.