Integer Overflow

Also known as:Integer Wraparound

Integer Overflow: A computation exceeds the range of its data type and wraps around to an incorrect value. The error is harmless in isolation but becomes dangerous as soon as the result feeds a length or bounds check.

How it works and where it fits

Integers have a fixed width. When a result exceeds the representable range, unsigned types wrap modulo, while signed overflow is undefined behaviour in C. The classic case is a size computation before an allocation: count * size overflows, the result becomes small, the buffer is allocated too short — and the subsequent copy writes past its end. Closely related are signedness errors where a negative value is interpreted as a very large unsigned length.

Practical security relevance

The finding almost never lies in the overflow itself but in its downstream effect: an undersized buffer, a skipped bounds check, a wrong loop counter. Remedies include checked arithmetic, validating before rather than after the computation, sufficiently wide types for size values, and static analysis. Assessment should always trace the path from the faulty value to the security-relevant decision.

  • Memory CorruptionMemory CorruptionUnintentional or targeted alteration of storage structures with security implications.: Unintentional or targeted alteration of storage structures with security implications.
  • Buffer OverflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data.: Writing beyond the bounds of a memory buffer, overwriting adjacent data.
  • Input ValidationInput ValidationVerification of input data regarding format, length, type, value range, and validity.: Verification of input data regarding format, length, type, value range, and validity.
  • Secure CodingSecure CodingProgramming practices aimed at avoiding common vulnerabilities and misconfigurations.: Programming practices aimed at avoiding common vulnerabilities and misconfigurations.