# Learn about the impact of stack buffer overflows

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/)
- [Introduction: "Smashing the stack"](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/introduction/)
- [Docker Setup](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/setup/)
- [Frame Layout](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/frame-layout/)
- [Stack Buffer Overflow](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/buffer-overflow/)
- [Redirect control flow](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/redirect-control-flow-1/)
- [Answers to exercises](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/exercise-answers/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/exploiting-stack-buffer-overflow-aarch64/_next-steps/)

## About this Learning Path

| Skill level:      | Advanced        |
|-------------------|-----------------|
| Reading time:     | 2 hrs           |
| Last updated:     | 13 Aug 2026     |

| Author:           | Kristof Beyls, Arm |
|-------------------|-----------------|
| Arm IP:           | [Neoverse](https://support.arm.com/?tab=compute-ip&Product%20Type=Infrastructure%20Processors) [Cortex-A](https://support.arm.com/?tab=compute-ip&Product%20Type=Application%20Processors) |
| Tags:             | [Performance and Architecture](/tag/performance-and-architecture) [Linux](/tag/linux) [Clang](/tag/clang) [C](/tag/c) [Assembly](/tag/assembly) [Runbook](/tag/runbook) |

### Who is this for?
This is an advanced topic for software developers interested in understanding how memory vulnerability-based exploits work on AArch64 and how to defend against them.

### What will you learn?
Upon completion of this Learning Path, you will be able to:

- Analyze the stack frame layout to derive which field in user input overwrites the return address stored on the stack.
- Build a basic end-to-end exploit by changing the return address to an attacker-controlled value.

### Prerequisites
Before starting, you will need the following:

- An Arm computer running linux with [Docker](/install-guides/docker/) installed.
- Some familiarity with reading and writing basic C code and AArch64 assembly code.
- Some familiarity with running linux command line commands.
- Some familiarity with using a gdb debugger.

### Summary
You’ll examine stack buffer overflows on AArch64 using small C programs in a Docker-based Linux environment. First, you’ll configure Clang and GDB, disable address space layout randomization for reproducible stacks, and inspect stack-frame layout. Then, you’ll craft input that overwrites a saved return address, observe redirected control flow, and see how ASLR affects the experiment.

### Frequently asked questions

<details>
<summary>Why is ASLR disabled in the container, and what happens if it's not?</summary>
ASLR randomizes addresses and blocks the reproducible redirection needed for these experiments. The Dockerfile writes a `sysctl` configuration to disable ASLR so the stack layout and addresses stay predictable.
</details>

<details>
<summary>How do I confirm the container is set up correctly before running the code?</summary>
Check that Clang and GDB are available in the container and that `/etc/sysctl.d/01-disable-aslr.conf` exists. You need these conditions to keep addresses stable across runs.
</details>

<details>
<summary>How do I figure out which input bytes reach the saved return address?</summary>
Use the stack-frame exercise to reason from the local buffer to the saved return address and derive the offset. Then, craft input that pads up to that offset before appending the value you intend to write.
</details>

<details>
<summary>What result should I expect to confirm the overflow behavior before redirecting control flow?</summary>
You should observe that writing past the end of the local buffer affects data beyond that buffer, including the saved return address.
</details>

<details>
<summary>What should I check if the redirect-control-flow example crashes instead of running the intended path?</summary>
Re-check the calculated offset and the exact bytes you wrote for the target return address. Also ensure the example code matches the provided text and that ASLR is disabled as configured in the container.
</details>
