logoalt Hacker News

taminkatoday at 3:22 PM4 repliesview on HN

this is amazing, counter to what most ppl think, majority of memory bugs are from out of bounds access, not stuff like forgetting to free a pointer or some such


Replies

Night_Thastustoday at 5:18 PM

Personally, as someone in C and C++ for the last few years, memory access is almost never the root bug. It's almost always logic errors. Not accounting for all paths, not handling edge cases, not being able to handle certain combinations of user or file input, etc.

Occasionally an out-of-bounds access pops up, but they're generally so blindingly obvious and easy to fix that it's never been the slow part of bug fixing.

show 2 replies
woodruffwtoday at 5:15 PM

"Majority" could mean a few things; I wouldn't be surprised if the majority of discovered memory bugs are spatial, but I'd expect the majority of widely exploited memory bugs to be temporal (or pseudo-temporal, like type confusions).

Retr0idtoday at 3:26 PM

I think UAFs are more common in mature software

show 1 reply
random_mutextoday at 3:31 PM

There is use after free

show 1 reply