Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An adversary can turn a double free into a use after free by causing an object to be allocated in-between the two free operations at the same address


You can't free a buffer/object twice in the proposal. After a free, you can't use the pointer any longer.

But it might very well be that this approach is not hard enough for use in e.g. the kernel. It might still be useful for userland applications, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: