cybersecurity · beginner · ~15 min

Safe Multiplication Overflow Guard

Detect and prevent unsigned and signed integer overflows before memory allocation.

Challenge

Integer overflow in buffer size calculations is a classic source of heap buffer overflows in C. Multiplying two positive integers a * b without checking if a > SIZE_MAX / b wraps around to a small number, causing undersized buffer allocations.

Your Task

Implement overflow-safe arithmetic operations:

int safe_size_multiply(size_t a, size_t b, size_t *out);
int safe_int_add(int a, int b, int *out);

Rules

  1. In safe_size_multiply:
    • If out == NULL, return -1.
    • If a == 0 or b == 0, set *out = 0 and return 0.
    • If a > SIZE_MAX / b, return -1 (multiplication overflow detected).
    • Set *out = a * b and return 0.
  2. In safe_int_add:
    • If out == NULL, return -1.
    • Detect signed integer overflow: if b > 0 && a > INT_MAX - b, return -1.
    • If b < 0 && a < INT_MIN - b, return -1.
    • Set *out = a + b and return 0.

Example

size_t res;
safe_size_multiply(100, 200, &res); // returns 0, res == 20000
safe_size_multiply(SIZE_MAX, 2, &res); // returns -1

Input format

a, b: operands; out: pointer to destination result.

Output format

Returns 0 on safe calculation, -1 on detected overflow or NULL pointer.

Constraints

Must check bounds before performing arithmetic operation.

Starter code

#include <stddef.h>
#include <stdint.h>
#include <limits.h>

int safe_size_multiply(size_t a, size_t b, size_t *out) {
    (void)a; (void)b; (void)out;
    return -1;
}
int safe_int_add(int a, int b, int *out) {
    (void)a; (void)b; (void)out;
    return -1;
}

Common mistakes

Performing multiplication first and checking result afterwards (undefined behavior in signed arithmetic).

Edge cases to handle

Multiplying by 0 never overflows; INT_MAX + 1 fails; INT_MIN - 1 fails.

Background lessons

Solve this exercise in the browser editor — compile and run against the test harness, no setup required.