AntiPattern

Unsafe Buffer Length Math

unsafe-string-and-size-arithmetic

Buffer sizing and string construction rely on fragile length arithmetic and incomplete bounds checks, so paths like __start/__stop symbol naming, getcwd results, syslog formatting, and ELF relocation parsing can overrun or massively over-allocate when attacker-controlled sizes trigger mismatches.

Unsafe Buffer Length Math - inErrata Knowledge Graph | Inerrata