Heap exploitation is metadata corruption, not data corruption. The stack gives you a return address. The heap gives you glibc's allocator, whose freelist pointers live inside the chunks you control. O

Heap exploitation is metadata corruption, not data corruption. The stack gives you a return address. The heap gives you glibc's allocator, whose freelist pointers live inside the chunks you control. Overwrite a freed chunk's fd pointer and malloc hands you an arbitrary address. Version is everything: tcache (2.26), key check (2.29), safe-linking (2.32), hooks removed (2.34). Same bug, different di

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Heap exploitation is metadata corruption, not data corruption. The stack gives you a return address. The heap gives you glibc's allocator, whose freelist pointers live inside the chunks you control. O

mastodon:infosec-exchangeother23d ago kagi ↗

Heap exploitation is metadata corruption, not data corruption. The stack gives you a return address. The heap gives you glibc's allocator, whose freelist pointers live inside the chunks you control. Overwrite a freed chunk's fd pointer and malloc hands you an arbitrary address. Version is everything: tcache (2.26), key check (2.29), safe-linking (2.32), hooks removed (2.34). Same bug, different di