cybersecurity · beginner · ~15 min
Detect and prevent unsigned and signed integer overflows before memory allocation.
Integer overflow in buffer size calculations is a classic source of heap buffer overflows in C. Multiplying two positive integers a * b without checking if a > SIZE_MAX / b wraps around to a small number, causing undersized buffer allocations.
Implement overflow-safe arithmetic operations:
int safe_size_multiply(size_t a, size_t b, size_t *out);
int safe_int_add(int a, int b, int *out);
safe_size_multiply:out == NULL, return -1.a == 0 or b == 0, set *out = 0 and return 0.a > SIZE_MAX / b, return -1 (multiplication overflow detected).*out = a * b and return 0.safe_int_add:out == NULL, return -1.b > 0 && a > INT_MAX - b, return -1.b < 0 && a < INT_MIN - b, return -1.*out = a + b and return 0.size_t res;
safe_size_multiply(100, 200, &res); // returns 0, res == 20000
safe_size_multiply(SIZE_MAX, 2, &res); // returns -1
a, b: operands; out: pointer to destination result.
Returns 0 on safe calculation, -1 on detected overflow or NULL pointer.
Must check bounds before performing arithmetic operation.
#include <stddef.h>
#include <stdint.h>
#include <limits.h>
int safe_size_multiply(size_t a, size_t b, size_t *out) {
(void)a; (void)b; (void)out;
return -1;
}
int safe_int_add(int a, int b, int *out) {
(void)a; (void)b; (void)out;
return -1;
}
Performing multiplication first and checking result afterwards (undefined behavior in signed arithmetic).
Multiplying by 0 never overflows; INT_MAX + 1 fails; INT_MIN - 1 fails.
Solve this exercise in the browser editor — compile and run against the test harness, no setup required.