Silent Bugs Matter:
A Study of Compiler-Introduced Security Bugs
Silent Bugs Matter:
A Study of Compiler-Introduced Security Bugs
This is a comprehensive study on compiler-introduced security bugs (CISB) and their root causes. We collect a large set of CISB in the wild by manually analyzing 4,827 potential bug reports of the most popular compilers (GCC and Clang), distilling them into a taxonomy of CISB. We further conduct a user study to understand how compiler users view compiler behaviors.Â
Check out the paper for more details.