Language-Level Memory Management (C/C++/Rust) Questions

How C and C++ expose and manage memory at the language level: pointers and pointer arithmetic, pointers to pointers and function pointers, arrays versus pointers and array decay, stack versus heap storage, manual allocation and freeing in C (malloc, realloc, free), new and delete versus malloc and free, placement new, RAII and owning smart pointers (unique_ptr, including custom deleters for C resources), shallow versus deep copies and move semantics in C++. Covers reasoning about who owns a buffer and designing ownership and lifetime contracts across function, library and plugin boundaries; dangling and uninitialized pointers, leaks, double frees, use-after-free, off-by-one errors and buffer overruns and how to prevent them; undefined behavior, strict aliasing and safe byte reinterpretation, endianness; struct layout, alignment and padding as the language defines them; and finding and diagnosing memory bugs with sanitizers, Valgrind-style tools, tracing allocators and heap-corruption triage, including allocator design and heap fragmentation at the language level. Boundary: garbage-collector behavior and tuning, embedded memory budgets, register access and packing structs to hardware layouts, OS virtual memory and paging, and lock-based concurrency are covered elsewhere.

EasyTechnical
65 practiced

What are the main techniques to prevent and detect buffer overflows in C beyond swapping in safer-looking library functions? Cover both coding practice and build-time or runtime defenses.

EasyTechnical
87 practiced

What is undefined behavior in C and C++, and why is it especially dangerous in code that handles untrusted input? Give examples that look harmless in review but can become exploitable or non-deterministic at runtime.

HardTechnical
70 practiced

You receive a crash report showing a use-after-free in a high-privilege security agent. Walk through how you would confirm the root cause, reproduce the issue, determine whether it is exploitable, and prioritize a fix without introducing regressions.

That is every published Language-Level Memory Management (C/C++/Rust) question for Penetration Tester so far. Browse the other topics in this category, or practice this one interactively.