You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux:简单C程序缓冲区溢出触发SIGBUS问题咨询

Why Your Buffer Overflow is Triggering SIGBUS Instead of SIGSEGV (and How to Fix It)

Hey there, let's break down why you're hitting a SIGBUS signal instead of the more common SIGSEGV when triggering your buffer overflow, and walk through solutions tailored to your training scenario.

First, a quick refresher on the two signals to set context:

  • SIGSEGV (Segmentation Fault) happens when you try to access a virtual memory address that doesn't exist, or you don't have permission to access it.
  • SIGBUS (Bus Error) occurs when you access a virtual memory address that's valid (exists in the address space) but can't be physically accessed—most often due to memory alignment issues or accessing a page that's mapped but not loaded into physical memory.

Common Causes for SIGBUS in Your Buffer Overflow

Let's tie this directly to your test program:

  1. Misaligned Return Address
    Most CPU architectures (like x86_64, ARM, MIPS) require instruction pointers (RIP/EIP) to point to aligned addresses (8-byte for x86_64, 4-byte for 32-bit x86). If your overflow payload sets the return address to an unaligned value (e.g., 0xdeadbeef1 instead of 0xdeadbeef0 on x86_64), the CPU will refuse to execute instructions from that address and throw a SIGBUS.

  2. Crossing Stack Page Boundaries
    Your buffer[64] lives on the stack, which is divided into fixed-size pages (usually 4KB). If your overflow exactly reaches the edge of a stack page and you try to access memory just beyond it, that adjacent page might be marked as "reserved but not mapped to physical memory"—leading to a SIGBUS instead of SIGSEGV (which would trigger if the page didn't exist at all).

  3. Unintended Compilation Protections
    If you didn't disable stack protections when compiling, features like stack canaries or page-based stack guards might alter how memory is accessed during overflow. While these usually trigger SIGSEGV, in edge cases they can lead to SIGBUS if they block access to a valid but protected page.

Fixes to Try

Here's how to resolve each issue for your training:

  • Ensure Address Alignment
    Double-check the return address you're overwriting with. For 32-bit programs, make sure it's a multiple of 4; for 64-bit, a multiple of 8. For example, if you're targeting a gadget at 0x401235, round it down to 0x401234 (if that's still a valid instruction) or adjust your payload to hit an aligned address.

  • Tweak Payload Length
    If you suspect you're hitting a page boundary, adjust the length of your input. For example, if you're sending 72 bytes to overflow the 64-byte buffer + 8-byte RIP, try sending 71 or 73 bytes to shift where the return address lands—ensuring it's fully within a mapped stack page.

  • Compile with Training-Friendly Flags
    Since you're doing beginner training, disable all memory protections to eliminate environmental variables. Compile your program with:

gcc -fno-stack-protector -z execstack -no-pie -o temp_cleaner temp_cleaner.c
  • -fno-stack-protector: Disables stack canaries

  • -z execstack: Makes the stack executable (so your shellcode runs if you inject it)

  • -no-pie: Disables position-independent execution, making addresses predictable

  • Debug with GDB to Confirm
    Fire up GDB and run your program with gdb ./temp_cleaner. When it hits SIGBUS, use:

    • info registers to check the value of RIP/EIP—verify if it's aligned
    • info proc mappings to check if the address in RIP/EIP is within a mapped memory region
    • x/10x <rip-value> to see if the memory at that address is accessible

Quick Note on Your Code

I noticed your system call line is cut off (system("/bin/rm -rf /tmp/*...)—make sure to finish that statement to avoid compilation errors, though it won't affect your overflow issue.


内容的提问来源于stack exchange,提问作者Nim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:28:28