npx skills add ...
npx skills add trailofbits/skills --skill address-sanitizer
Builds and runs code under AddressSanitizer to catch buffer overflows, use-after-free, and other memory errors during fuzzing or tests. Covers -fsanitize=address builds, ASAN_OPTIONS, reading the crash report, LeakSanitizer, and the overhead and platform trade-offs. Use when fuzzing C/C++ or Rust that has unsafe blocks or FFI, when debugging a memory corruption crash, or when reading an ASan stack trace.
npx skills add trailofbits/skills --skill address-sanitizer
AddressSanitizer (ASan) is a widely adopted memory error detection tool used extensively during software testing, particularly fuzzing. It helps detect memory corruption bugs that might otherwise go unnoticed, such as buffer overflows, use-after-free errors, and other memory safety violations.
ASan is a standard practice in fuzzing due to its effectiveness in identifying memory vulnerabilities. It instruments code at compile time to track memory allocations and accesses, detecting illegal operations at runtime.
| Concept | Description |
|---|---|
| Instrumentation | ASan adds runtime checks to memory operations during compilation |
| Shadow Memory | Maps 20TB of virtual memory to track allocation state |
| Performance Cost | Approximately 2-4x slowdown compared to non-instrumented code |
| Detection Scope | Finds buffer overflows, use-after-free, double-free, and memory leaks |
Apply this technique when:
Skip this technique when:
| Task | Command/Pattern |
|---|---|
| Enable ASan (Clang/GCC) | -fsanitize=address |
| Enable verbosity | ASAN_OPTIONS=verbosity=1 |
| Disable leak detection | ASAN_OPTIONS=detect_leaks=0 |
| Force abort on error | ASAN_OPTIONS=abort_on_error=1 |
| Multiple options | ASAN_OPTIONS=verbosity=1:abort_on_error=1 |
Compile and link your code with the -fsanitize=address flag:
The -g flag is recommended to get better stack traces when ASan detects errors.
Set the ASAN_OPTIONS environment variable to configure ASan behavior:
Execute the ASan-instrumented binary. When memory errors are detected, ASan will print detailed reports:
ASan requires approximately 20TB of virtual memory. Disable fuzzer memory restrictions:
-rss_limit_mb=0-m noneUse Case: Standard fuzzing setup with ASan
Before:
After:
Use Case: Enable ASan for unit test suite
Before:
After:
| Tip | Why It Helps |
|---|---|
Use -g flag | Provides detailed stack traces for debugging |
Set verbosity=1 | Confirms ASan is enabled before program starts |
| Disable leaks during fuzzing | Leak detection doesn't cause immediate crashes, clutters output |
Enable abort_on_error=1 | Some fuzzers require abort() instead of _exit() |
When ASan detects a memory error, it prints a detailed report including:
Example ASan report:
ASan can be combined with other sanitizers for comprehensive detection:
Linux: Full ASan support with best performance macOS: Limited support, some features may not work Windows: Experimental support, not recommended for production fuzzing
| Anti-Pattern | Problem | Correct Approach |
|---|---|---|
| Using ASan in production | Can make applications less secure | Use ASan only for testing |
| Not disabling memory limits | Fuzzer may kill process due to 20TB virtual memory | Set -rss_limit_mb=0 or -m none |
| Ignoring leak reports | Memory leaks indicate resource management issues | Review leak reports at end of fuzzing campaign |
Compile with both fuzzer and address sanitizer:
Run with unlimited RSS:
Integration tips:
-fsanitize=fuzzer with -fsanitize=address-g for detailed stack traces in crash reportsASAN_OPTIONS=abort_on_error=1 for better crash handlingSee: libFuzzer: AddressSanitizer
Use the AFL_USE_ASAN environment variable:
Run with unlimited memory:
Integration tips:
AFL_USE_ASAN=1 automatically adds proper compilation flags-m none to disable AFL++'s memory limitAFL_MAP_SIZE for programs with large coverage mapsUse the --sanitizer=address flag:
Or configure in fuzz/Cargo.toml:
Integration tips:
See: cargo-fuzz: AddressSanitizer
Compile with ASan and link with honggfuzz:
Compile the target:
Integration tips:
| Issue | Cause | Solution |
|---|---|---|
| Fuzzer kills process immediately | Memory limit too low for ASan's 20TB virtual memory | Use -rss_limit_mb=0 (libFuzzer) or -m none (AFL++) |
| "ASan runtime not initialized" | Wrong linking order or missing runtime | Ensure -fsanitize=address used in both compile and link |
| Leak reports clutter output | LeakSanitizer enabled by default | Set ASAN_OPTIONS=detect_leaks=0 |
| Poor performance (>4x slowdown) | Debug mode or unoptimized build | Compile with -O2 or -O3 alongside -fsanitize=address |
| ASan not detecting obvious bugs | Binary not instrumented | Check with ASAN_OPTIONS=verbosity=1 that ASan prints startup info |
| False positives | Interceptor conflicts | Check ASan FAQ for known issues with specific libraries |
| Skill | How It Applies |
|---|---|
| libfuzzer | Compile with -fsanitize=fuzzer,address for integrated fuzzing with memory error detection |
| aflpp | Use AFL_USE_ASAN=1 environment variable during compilation |
| cargo-fuzz | Use --sanitizer=address flag to enable ASan for Rust fuzz targets |
| honggfuzz | Compile target with -fsanitize=address for ASan-instrumented fuzzing |
| Skill | Relationship |
|---|---|
| undefined-behavior-sanitizer | Often used together with ASan for comprehensive bug detection (undefined behavior + memory errors) |
| fuzz-harness-writing | Harnesses must be designed to handle ASan-detected crashes and avoid false positives |
| coverage-analysis | Coverage-guided fuzzing helps trigger code paths where ASan can detect memory errors |
AddressSanitizer on Google Sanitizers Wiki
The official ASan documentation covers:
Common configuration flags shared across all sanitizers:
verbosity: Control diagnostic output levellog_path: Redirect sanitizer output to filessymbolize: Enable/disable symbol resolution in reportsexternal_symbolizer_path: Use custom symbolizerASan-specific configuration options:
detect_leaks: Control memory leak detectionabort_on_error: Call abort() vs _exit() on errordetect_stack_use_after_return: Detect stack use-after-return bugscheck_initialization_order: Find initialization order bugsCommon pitfalls and solutions:
Clang AddressSanitizer Documentation
Clang-specific guidance:
GCC-specific ASan documentation:
AddressSanitizer: A Fast Address Sanity Checker (USENIX Paper)
Original research paper with technical details:
./my_programclang -o fuzz_target fuzz_target.c
./fuzz_targetclang -fsanitize=address -g -o fuzz_target fuzz_target.c
ASAN_OPTIONS=verbosity=1:abort_on_error=1 ./fuzz_targetgcc -o test_suite test_suite.c -lcheck
./test_suitegcc -fsanitize=address -g -o test_suite test_suite.c -lcheck
ASAN_OPTIONS=detect_leaks=1 ./test_suite==12345==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x60300000eff4 at pc 0x00000048e6a3
READ of size 4 at 0x60300000eff4 thread T0
#0 0x48e6a2 in main /path/to/file.c:42clang -fsanitize=address,undefined -g -o fuzz_target fuzz_target.cclang++ -fsanitize=fuzzer,address -g harness.cc -o fuzz./fuzz -rss_limit_mb=0AFL_USE_ASAN=1 afl-clang-fast++ -g harness.cc -o fuzzafl-fuzz -m none -i input_dir -o output_dir ./fuzzcargo fuzz run fuzz_target --sanitizer=address[profile.release]
opt-level = 3
debug = truehonggfuzz -i input_dir -o output_dir -- ./fuzz_target_asanhfuzz-clang -fsanitize=address -g target.c -o fuzz_target_asan