Lune

USENIX Security2026Top-tier venue

An Integer Overflow Endgame: Compiler and Architecture Support for Default-On Integer Overflow Mitigation

Zheng Zhang, Qi Ling, Kian Kasad, Brendan Ryan Sweeney, Deepak Gupta, Tal Garfinkel, Kazem Taram

2026Year

Abstract

Integer overflow checks are off-by-default in most production settings due to their high overheads. Consequently, many serious vulnerabilities remain unmitigated. We analyze the source of these overheads---in compilers including LLVM (UBSan, Rust), and in processors including x86-64, ARM64, and RISC-V---and show how to eliminate them. Overheads in LLVM stem from how overflow semantics are expressed in LLVM IR. LLVM's current approach, based on intrinsics and branches, interferes with a variety of middle end optimizations. We develop an alternative approach that tracks overflow semantics with metadata, but otherwise leaves LLVM IR unchanged, eliminating this overhead. Overheads in hardware primarily result from current ISA designs, that require doubling the number of μops for checked vs. unchecked arithmetic, stressing the processor pipeline. We show how simple ISA extensions can alleviate this stress, enabling overflow-checked arithmetic to issue as a single μop. We evaluate these extensions through compiler-based emulation on real hardware and simulation in gem5. Our work offers a path to significantly reducing the cost of overflow checks in existing compilers, and demonstrates that integer overflow mitigation can be cheap enough for default-on use in future hardware.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 1961f84e-8b2f-4019-af56-52b32f6aad4d

Builds on3

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines