Alex Rivera | Logout

Why don't stacks grow upwards (for security)?

Asked 2010-04-30T12:35:31.297
29

This is related to the question 'Why do stacks typically grow downwards?', but more from a security point of view. I'm generally referring to x86.

It strikes me as odd that the stack would grow downwards, when buffers are usually written to upwards in memory. For example a typical C++ string has its end at a higher memory address than the beginning.

This means that if there's a buffer overflow you're overwriting further up the call stack, which I understand is a security risk, since it opens the possibility of changing return addresses and local variable contents.

If the stack grew upwards in memory, wouldn't buffer overflows simply run in to dead memory? Would this improve security? If so, why hasn't it been done? What about x64, do those stacks grow upwards and if not why not?

Edit
Report

2 Answers

3

Well, I don't know if the stack growth direction would have much effect on security, but if you look at machine architecture, growing the stack in the negative address direction really simplifies calling conventions, stack frame pointers, local variable allocation, etc. etc.

answered 2010-05-07T20:13:47.187
1

Probably because the architecture for most CPUs was designed in a time when men were men, and you could trust your programmers to not want to steal people's credit card numbers... it's mostly too late to change now (though as you say, it probably could been done for new architectures like Itanium which actually has two stacks!)

answered 2010-04-30T12:42:17.893

Your Answer