Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Security, probably. UAF attacks are going to be slightly harder to perform if the data you put there is zeroes now.


>UAF attacks are going to be slightly harder to perform

SOME attacks are going to be harder, others are going to be easier(at least that's what a Project Zero researcher thinks)

https://twitter.com/ifsecure/status/1572902862128295937


If they “worked until now” doesn’t that imply that the app ecosystem makes too little use of sanitizers like ASAN? Sanitizers will stomp on deallocated regions, and much much more.


That appears to be the effect of changes to calloc, though. The change to free is a security improvement.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: