Bibliography

The following bibliography contains standards, technical documentation, vulnerability taxonomies, research, and further reading relevant to the concepts discussed throughout this book.

C Language and Language Semantics

1. International Organization for Standardization. ISO/IEC 9899:2024: Information technology — Programming languages — C. 5th ed., 2024.

2. ISO/IEC JTC1/SC22/WG14. C Language Working Documents and Papers. International Organization for Standardization.

3. SEI CERT. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute. Current online edition.

Secure C Programming

4. SEI CERT. INT30-C. Ensure that unsigned integer operations do not wrap. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

5. SEI CERT. INT32-C. Ensure that operations on signed integers do not result in overflow. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

6. SEI CERT. EXP08-C. Ensure pointer arithmetic is used correctly. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

7. SEI CERT. ARR30-C. Do not form or use out-of-bounds pointers or array subscripts. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

8. SEI CERT. MEM30-C. Do not access freed memory. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

9. SEI CERT. MEM31-C. Free dynamically allocated memory when no longer needed. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

10. SEI CERT. MEM34-C. Only free memory allocated dynamically. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

11. SEI CERT. MEM35-C. Allocate sufficient memory for an object. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

12. SEI CERT. MSC15-C. Do not depend on undefined behavior. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

Vulnerability Taxonomies

13. MITRE. Common Weakness Enumeration (CWE). Version 4.20, 2026.

14. MITRE. CWE-122: Heap-based Buffer Overflow. Common Weakness Enumeration.

15. MITRE. CWE-125: Out-of-bounds Read. Common Weakness Enumeration.

16. MITRE. CWE-190: Integer Overflow or Wraparound. Common Weakness Enumeration.

17. MITRE. CWE-415: Double Free. Common Weakness Enumeration.

18. MITRE. CWE-416: Use After Free. Common Weakness Enumeration.

19. MITRE. CWE-787: Out-of-bounds Write. Common Weakness Enumeration.

20. MITRE. CWE-1399: Comprehensive Categorization: Memory Safety. Common Weakness Enumeration.

Dynamic Analysis and Debugging

21. LLVM Project. AddressSanitizer. LLVM Clang Documentation.

22. LLVM Project. UndefinedBehaviorSanitizer. LLVM Clang Documentation.

23. LLVM Project. MemorySanitizer. LLVM Clang Documentation.

24. Valgrind Developers. Valgrind User Manual. Release 3.27.1, 2026.

Memory-Safe Language Design

25. Klabnik, Steve, Carol Nichols, and Chris Krycho, with contributions from the Rust community. The Rust Programming Language. Current online edition.

26. The Rust Project. What Is Ownership? The Rust Programming Language.

27. The Rust Project. The Slice Type. The Rust Programming Language.

28. The Go Authors. A Guide to the Go Garbage Collector. Go Programming Language documentation.

Capability-Based Memory Safety

29. Watson, Robert N. M., Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie, Steven J. Murdoch, Robert Norton, Michael Roe, Stacey Son, and Munraj Vadera. CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. 2015 IEEE Symposium on Security and Privacy, 20–37, 2015. doi:10.1109/SP.2015.9.

30. Watson, Robert N. M., Alexander Richardson, Brooks Davis, John Baldwin, David Chisnall, Jessica Clarke, Nathaniel Filardo, Simon W. Moore, Edward Napierala, Allison Randal, Peter Sewell, and Peter G. Neumann. CHERI C/C++ Programming Guide. Technical Report UCAM-CL-TR-947, University of Cambridge, Computer Laboratory, June 2020.

31. Watson, Robert N. M., Simon W. Moore, Peter Sewell, and Peter G. Neumann. An Introduction to CHERI. Technical Report UCAM-CL-TR-941, University of Cambridge, Computer Laboratory, 2019.

The OpenAI-Hugging Face Incident

32. Wallace, Eric, and Michael Dalton. The ‘Breaking’ News: The OpenAI–Hugging Face Incident. Black Hat USA 2026, August 6, 2026. See slide 13, “June 26th Artifactory RCE detail,” approximately 14:00–14:30 in the recording.

33. Hugging Face. Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident. July 27, 2026.

34. OpenAI. OpenAI and Hugging Face partner to address security incident during model evaluation. July 21, 2026.

Further Reading

35. LLVM Project. Clang Compiler User’s Manual. LLVM Project documentation.

36. Software Engineering Institute. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

37. Kern, Christoph. Safe Coding: Rigorous Modular Reasoning about Software Safety (Extended Version). Google Security Engineering, 2025.

38. Pirry, Conor, Hector Marco-Gisbert, and Carolyn Begg. A Review of Memory Errors Exploitation in x86-64. Computers 9, no. 2 (2020): 48. doi:10.3390/computers9020048.

39. Chromium Security Team. The Rule of 2. Chromium Security documentation, 2025.


← Previous Cover →