Evaluating the Effectiveness of Memory Safety Sanitizers
Emanuel Q. Vintila, Philipp Zieris, Julian Horsch
Abstract
C and C++ are programming languages designed for developing high-performance applications, such as web browsers and operating systems. This performance is partly achieved by sacrificing memory safety, which introduces the risk of memory bugs-the root cause of many of today's most severe vulnerabilities. Numerous solutions have been proposed to detect and prevent memory bugs, with the most effective employing dynamic program analysis to sanitize memory accesses. These memory safety sanitizers vary greatly in their capabilities, covering different memory regions and detecting different subsets of memory bugs. While conceptual classi-fications of these sanitizers exist, practical and quantitative evaluations have primarily focused on performance rather than their actual bug-finding capabilities. To bridge this gap, we present MSET, a tool for evaluating memory safety sanitizers, along with an extensive functional evaluation of the most powerful and widely used memory safety sanitizers. We systematically deconstruct memory safety bugs into distinct properties, such as the memory region, the method of memory corruption, and the type of access to the target buffer. Using this systematization, our tool generates test cases that combine small and unique code templates, covering all typical memory bugs, including various forms of buffer overflows, underflows, and use-after-frees. Our functional eval-uation highlights the differences between the conceptual de-tection potential of sanitization techniques and the bug-finding capabilities of sanitizers with similar objectives. Furthermore, it reveals that multiple sanitizers fail to achieve their conceptual potential due to incomplete or faulty implementations. Our tool is available as open source software, enabling researchers and practitioners to test their sanitizers and uncover lost potential, conceptual shortcomings, and implementation errors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 96586bff-77ac-4302-8ecd-c9ab7209f8a9Cited by top-tier papers3
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg et al.CCS 2026 · 3 citations
- SafeFFI: Efficient Sanitization at the Boundary Between Safe and Unsafe Code in Rust and Mixed-Language ApplicationsOliver Braunsdorf, Tim Lange, Konrad Hohentanner, Julian Horsch et al.USENIX Security 2026
- Fast Pointer Nullification for Use-After-Free PreventionYubo Du, Youtao Zhang, Jun YangNDSS 2026
Related papers
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Enhancing Memory Error Detection for Large-Scale Applications and Fuzz TestingWookhyun Han, Byunggill Joe, Byoungyoung Lee, Chengyu Song et al.NDSS 2018 · 33 citations
- Runtime detection of memory errors with smart statusZhe Chen, Chong Wang, Junqi Yan, Yulei Sui et al.ISSTA 2021 · 16 citations
- FloatZone: Accelerating Memory Error Detection using the Floating Point UnitFloris Gorter, Enrico Barberis, Raphael Isemann, Erik van der Kouwe et al.USENIX Security 2023
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
