Stack Canary
Also known as:Stack Cookie · Stack Protector
Stack Canary: Random guard value placed before the return address whose modification reveals a stack overflow. The canary is a detection measure, not a prevention measure against the buffer overflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data..
How it works and where it fits
On entering a function the compiler places a random value between the local variables and the saved return address. Before returning, it checks whether that value is unchanged. A linear overflow that wants to reach the return address must necessarily overwrite the canary as well — the check fails and the process aborts in a controlled way. The value is generated per process and usually contains a null byte so that string-based copy routines do not accidentally leak it.
Practical security relevance
The protection falls as soon as the attacker knows the value or does not need to overwrite it at all. A format string vulnerabilityFormat String VulnerabilityFlawed processing of user-controlled format strings, potentially allowing unauthorized memory access. reads the canary straight off the stack; it can then be reinserted unchanged during the overflow. Non-linear writes, for example through a controlled index, bypass the canary entirely. For assessment this means: an enabled stack protector is a hardening feature, not evidence that an overflow vulnerability is unexploitable.
Related concepts
- Buffer OverflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data.: Writing beyond the bounds of a memory buffer, overwriting adjacent data.
- Memory CorruptionMemory CorruptionUnintentional or targeted alteration of storage structures with security implications.: Unintentional or targeted alteration of storage structures with security implications.
- Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.
- HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.