Bibliography

The following bibliography contains standards, technical documentation, vulnerability taxonomies, research, and further reading relevant to the concepts discussed throughout this book.

C Language and Language Semantics

1. International Organization for Standardization. ISO/IEC 9899:2024: Information technology — Programming languages — C. 5th ed., 2024.

2. ISO/IEC JTC1/SC22/WG14. C Language Working Documents and Papers. International Organization for Standardization.

3. SEI CERT. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute. Current online edition.

Secure C Programming

4. SEI CERT. INT30-C. Ensure that unsigned integer operations do not wrap. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

5. SEI CERT. INT32-C. Ensure that operations on signed integers do not result in overflow. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

6. SEI CERT. EXP08-C. Ensure pointer arithmetic is used correctly. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

7. SEI CERT. ARR30-C. Do not form or use out-of-bounds pointers or array subscripts. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

8. SEI CERT. MEM30-C. Do not access freed memory. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

9. SEI CERT. MEM31-C. Free dynamically allocated memory when no longer needed. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

10. SEI CERT. MEM34-C. Only free memory allocated dynamically. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

11. SEI CERT. MEM35-C. Allocate sufficient memory for an object. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

12. SEI CERT. MSC15-C. Do not depend on undefined behavior. SEI CERT C Coding Standard. Carnegie Mellon University Software Engineering Institute.

Vulnerability Taxonomies

13. MITRE. Common Weakness Enumeration (CWE). Version 4.20, 2026.

14. MITRE. CWE-122: Heap-based Buffer Overflow. Common Weakness Enumeration.

15. MITRE. CWE-125: Out-of-bounds Read. Common Weakness Enumeration.

16. MITRE. CWE-190: Integer Overflow or Wraparound. Common Weakness Enumeration.

17. MITRE. CWE-415: Double Free. Common Weakness Enumeration.

18. MITRE. CWE-416: Use After Free. Common Weakness Enumeration.

19. MITRE. CWE-787: Out-of-bounds Write. Common Weakness Enumeration.

20. MITRE. CWE-1399: Comprehensive Categorization: Memory Safety. Common Weakness Enumeration.

Dynamic Analysis and Debugging

21. LLVM Project. AddressSanitizer. LLVM Clang Documentation.

22. LLVM Project. UndefinedBehaviorSanitizer. LLVM Clang Documentation.

23. LLVM Project. MemorySanitizer. LLVM Clang Documentation.

24. Valgrind Developers. Valgrind User Manual. Release 3.27.1, 2026.

Memory-Safe Language Design

25. Klabnik, Steve, Carol Nichols, and Chris Krycho, with contributions from the Rust community. The Rust Programming Language. Current online edition.

26. The Rust Project. Understanding Ownership. The Rust Programming Language.

27. The Rust Project. The Slice Type. The Rust Programming Language.

28. The Go Authors. A Guide to the Go Garbage Collector. Go Programming Language documentation.

Capability-Based Memory Safety

29. Watson, Robert N. M., Simon W. Moore, Peter Sewell, and Peter G. Neumann. CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. 2015 IEEE Symposium on Security and Privacy, 20–37, 2015. https://doi.org/10.1109/SP.2015.9.

30. The CHERI Project. CHERI C/C++ Programming Guide. University of Cambridge and SRI International.

31. Watson, Robert N. M., Simon W. Moore, Peter Sewell, and Peter G. Neumann. An Introduction to CHERI. University of Cambridge Computer Laboratory.

Further Reading

32. LLVM Project. Clang Compiler User's Manual. LLVM Project documentation.

33. SEI CERT. SEI CERT C Coding Standard — Memory Management (MEM). Carnegie Mellon University Software Engineering Institute.

34. Kern, Christoph. Safe Coding: Rigorous Modular Reasoning about Software Safety (Extended Version). Google Security Engineering, 2025.


← Previous Cover →