Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms
Christian Wressnegger, Fabian Yamaguchi, Alwin Maier, Konrad Rieck
Abstract
Subtle flaws in integer computations are a prime source for exploitable vulnerabilities in system code. Unfortunately, even code shown to be secure on one platform can be vulnerable on another, making the migration of code a notable security challenge. In this paper, we provide the first study on how code that works as expected on 32-bit platforms can become vulnerable on 64-bit platforms. To this end, we systematically review the effects of data model changes between platforms. We find that the larger width of integer types and the increased amount of addressable memory introduce previously non-existent vulnerabilities that often lie dormant in program code. We empirically evaluate the prevalence of these flaws on the source code of Debian stable ("Jessie") and 200 popular open-source projects hosted on GitHub. Moreover, we discuss 64-bit migration vulnerabilities that have been discovered as part of our study, including vulnerabilities in Chromium, the Boost C++ Libraries, libarchive, the Linux Kernel, and zlib.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62024d60-544a-4e9c-a2d8-9bd410d19084Cited by top-tier papers3
- DR. CHECKER: A Soundy Analysis for Linux Kernel DriversAravind Machiry, Chad Spensky, Jake Corina, Nick Stephens et al.USENIX Security 2017 · 126 citations
- Check It Again: Detecting Lacking-Recheck Bugs in OS KernelsWenwen Wang, Kangjie Lu, Pen-Chung YewCCS 2018 · 49 citations
- LLM-based Vulnerability Discovery through the Lens of Code MetricsFelix Weissberg, Lukas Pirch, Erik Imgrund, Jonas Möller et al.ICSE 2026
Related papers
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- Insight: Exploring Cross-Ecosystem Vulnerability ImpactsMeiqiu Xu, Ying Wang, Shing-Chi Cheung, Hai Yu et al.ASE 2022 · 12 citations
- Arbiter: Bridging the Static and Dynamic Divide in Vulnerability Discovery on Binary ProgramsJayakrishna Vadayath, Moritz Eckert, Kyle Zeng, Nicolaas Weideman et al.USENIX Security 2022
- How Long Do Vulnerabilities Live in the Code? A Large-Scale Empirical Measurement Study on FOSS Vulnerability LifetimesNikolaos Alexopoulos, Manuel Brack, Jan Philipp Wagner, Tim Grube et al.USENIX Security 2022
- Why Security Defects Go Unnoticed during Code Reviews? A Case-Control Study of the Chromium OS ProjectRajshakhar Paul, Asif Kamal Turzo, Amiangshu BosuICSE 2021 · 2 citations
