Fat Pointers for Temporal Memory Safety of C
Jie Zhou, John Criswell, Michael Hicks
Abstract
Temporal memory safety bugs, especially use-after-free and double free bugs, pose a major security threat to C programs. Real-world exploits utilizing these bugs enable attackers to read and write arbitrary memory locations, causing disastrous violations of confidentiality, integrity, and availability. Many previous solutions retrofit temporal memory safety to C, but they all either incur high performance overhead and/or miss detecting certain types of temporal memory safety bugs.
In this paper, we propose a temporal memory safety solution that is both efficient and comprehensive. Specifically, we extend Checked C, a spatially-safe extension to C, with temporally-safe pointers. These are implemented by combining two techniques: fat pointers and dynamic key-lock checks. We show that the fat-pointer solution significantly improves running time and memory overhead compared to the disjointmetadata approach that provides the same level of protection. With empirical program data and hands-on experience porting real-world applications, we also show that our solution is practical in terms of backward compatibility-one of the major complaints about fat pointers.
CCS Concepts: • Security and privacy → Software security engineering; • Software and its engineering → General programming languages.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 373b7994-fee9-4353-b219-2f65d6149b6dCited by top-tier papers10
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.CCS 2024 · 3 citations
- Safeslab: Mitigating Use-After-Free Vulnerabilities via Memory Protection KeysMarius Momeu, Simon Schnückel, Kai Angnis, Michalis Polychronakis et al.CCS 2024 · 3 citations
- Cpp2Rust: Automatic Translation of C++ to Safe RustLucian Popescu, Francisco Gouveia, Henrique Preto, João Silveira et al.PLDI 2026 · 1 citation
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.S&P 2025
- Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)Sourag Cherupattamoolayil, Arunkumar Bhattar, Connor Glosner, Aravind MachiryISSTA 2025
Builds on15
- PtrSplit: Supporting General Pointers in Automatic Program PartitioningShen Liu, Gang Tan, Trent JaegerCCS 2017 · 83 citations
- How do programmers use unsafe rust?Vytautas Astrauskas, Christoph Matheja, Federico Poli, Peter Müller et al.OOPSLA 2020 · 78 citations
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 77 citations
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin et al.CCS 2017 · 71 citations
Related papers
- In-fat pointer: hardware-assisted tagged-pointer spatial memory safety defense with subobject granularity protectionShengjie Xu, Wei Huang, David LieASPLOS 2021 · 26 citations
- C to checked C by 3cAravind Machiry, John H. Kastner, Matt McCutchen, Aaron Eline et al.OOPSLA 2022 · 20 citations
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang et al.CCS 2022 · 30 citations
- Catamaran: Low-Overhead Memory Safety Enforcement via Parallel AccelerationYiyu Zhang, Tianyi Liu, Zewen Sun, Zhe Chen et al.ISSTA 2023 · 3 citations
- Look Before You Access: Efficient Heap Memory Safety for Embedded Systems on ARMv8-MJeonghwan Kang, Jaeyeol Park, Jiwon Seo, Donghyun KwonDAC 2024 · 1 citation
