CLI Baseline B11 - memory-safety defect (instrumentation-dependent)
cli-baseline-b11-memory-safety is a critical severity check in the
cli-baseline category, written in shell.
Its source is templates/cli-baseline/cli-baseline-b11-memory-safety.sh in
cert-x-gen-templates.
What it checks
Section titled “What it checks”Drives over-length and boundary-shaped input at every argument and stdin, and reads the sanitizer runtime’s verdict. Declares sanitizer oracles so cxg skips it honestly on a build that cannot show the defect.
Header
Section titled “Header”| Field | Value |
|---|---|
| Id | cli-baseline-b11-memory-safety |
| Severity | critical |
| Language | shell |
| Category | cli-baseline |
| Author | CERT-X-GEN / CLI Security Baseline |
| Template version | not recorded |
| Confidence | not recorded |
| CVSS | not recorded |
| Weakness | CWE-787 |
| Tags | cli, baseline, memory-safety, cwe-787, cwe-125, cwe-416, instrumentation-dependent |
| Target kind | cli |
| Oracle | asan, ubsan, msan, tsan, overflow |
The file declares @allow_nonzero_exit as well. Those are not tabled above; read the
source for what they carry.
Run it
Section titled “Run it”To see what the copy on your machine says about itself, and to confirm it is installed at all:
cxg template info cli-baseline-b11-memory-safetyThe id it prints is the one to pass anywhere a template is selected. See
cxg template for the rest of
the subcommand, Scan a target for running
a scan, and
A match is not a finding for how
to read what comes back.
Related
Section titled “Related”- Template catalog is the whole corpus.
- cli-baseline is the rest of this category.
- Templates by weakness class groups checks by the defect they look for.
- Contribute a template is the route from a check you needed and could not find to a merged one.

