Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Automation software engineering and architecture

Buffer overflow

Also known as: Buffer overrun

German: Pufferüberlauf

In software engineering, a buffer overflow is a defect in which a program writes data beyond the bounds of an allocated memory buffer, overwriting adjacent memory. It can cause crashes and undefined behavior and is a common source of security vulnerabilities that allow attackers to execute code.

  • Software engineering
  • OT security

In one sentence

A buffer overflow occurs when a program writes past the end of a memory buffer, corrupting adjacent memory and often creating vulnerabilities.

Example

A device's web server copies an unchecked request header into a fixed-size array; an overlong header overwrites the stack and crashes the communication module.

How it applies

  • Engineering: Buffer overflows mainly occur in languages without automatic bounds checking, such as C and C++, which are widely used in firmware, drivers and communication stacks. Bounds checks, safe library functions, coding standards and static analysis reduce the risk.
  • Security: Many published vulnerabilities in industrial devices are buffer overflows in network-facing code. IEC 62443 expects secure development practices, and fixed vulnerabilities reach the field through Patch management.
  • Documentation: Security advisories and release notes should name affected versions, the fixed version and interim mitigations. The documentation team should make sure update instructions are easy to find for operators.

Buffer overflow vs. integer overflow

An Integer overflow happens when an arithmetic result exceeds the range of its data type. It can lead to a buffer overflow when the wrong result is used as a buffer size or index, which is why both are often found together in vulnerability reports.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on secure software development practice (IEC 62443-4-1 context)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!