QuickSafe: Targeted Hardening Against Memory Corruption
Johannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert Bos
Abstract
Despite decades of research, memory safety solutions see limited adoption, as they often incur high overheads, are complex to deploy, or cover only a narrow scope of bugs. In this paper, we present QuickSafe — a targeted approach to harden programs against exploitation of known but unresolved memory errors with minimal overhead. QuickSafe yields a stopgap patch that is immediately available, while the bug awaits eventual resolution. Where most existing automatic patch generators rely on inserting runtime constraint checks in the code to stop exploits, QuickSafe instead isolates memory objects associated with a known bug from the rest of the program. Object isolation can be implemented in different ways, depending on hardware support and desired security guarantees. To assess the viability, we present two such implementations. On traditional architectures, we allocate vulnerable objects on dedicated pages flanked by inaccessible guard pages. On platforms that support Memory Tagging Extensions (MTE), we offer stronger guarantees by enforcing disjoint tag domains. To reliably identify the objects associated with a given memory error, we introduce TagASan — an extension of AddressSanitizer (ASan) that uses tagged pointers to trace faulting accesses back to their originating allocation sites. As an additional contribution, we present a new dataset of 223 real-world memory errors across ten prominent projects to measure the performance of automatic patch generators. We evaluate QuickSafe on (1) this new benchmark suite, (2) the Juliet Test Suite, and (3) buggy benchmarks from SPEC CPU2006/2017. Using the guard-page-based isolation backend, QuickSafe protects against the exploitation of all evaluated bugs, incurring a geomean memory overhead of 2.46 % and a geomean runtime overhead of 2.67 % - with the vast majority of applications slowing down by only around 1 %. We apply the MTE-based isolation strategy to a representative subset of the dataset, confirming its effectiveness and showing negligible runtime overhead of .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19c63d3e-2afa-4376-971f-070e478a8a62Builds on26
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Stack Bounds Protection with Low Fat PointersGregory J. Duck, Roland H. C. Yap, Lorenzo CavallaroNDSS 2017 · 121 citations
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 77 citations
- PTAuth: Temporal Memory Safety via Robust Points-to AuthenticationReza Mirzazade Farkhani, Mansour Ahmadi, Long LuUSENIX Security 2021 · 67 citations
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 63 citations
Related papers
- MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS BinariesXingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li et al.USENIX Security 2023
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana et al.S&P 2026 · 1 citation
- Practical Object-Level Sanitizer with Aggregated Memory Access and Custom AllocatorXiaolei Wang, Ruilin Li, Bin Zhang, Chao Feng et al.ICSE 2025
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 22 citations
- RangeSanitizer: Detecting Memory Errors with Efficient Range ChecksFloris Gorter, Cristiano GiuffridaUSENIX Security 2025
