'\" t .\" Copyright 1993, David Metcalfe .\" Copyright, the authors of the Linux man-pages project .\" .\" SPDX-License-Identifier: Linux-man-pages-copyleft .\" .TH memcmp 3 2026-08-10 "Linux man-pages 6.19" .SH NAME memcmp \- memory compare .SH LIBRARY Standard C library .RI ( libc ,\~ \-lc ) .SH SYNOPSIS .nf .BR #include\~ " // see memory.h(3head)" .P .BR "int memcmp(" "size_t n;" .BI " const void " s1 [ n "], const void " s2 [ n "], size_t " n ); .fi .SH DESCRIPTION The .BR memcmp () function compares the first .I n bytes (each interpreted as .IR "unsigned\ char" ) of the memory areas .I s1 and .IR s2 . .SH RETURN VALUE The .BR memcmp () function returns an integer less than, equal to, or greater than zero if the first .I n bytes of .I s1 is found, respectively, to be less than, to match, or be greater than the first .I n bytes of .IR s2 . .P For a nonzero return value, the sign is determined by the sign of the difference between the first pair of bytes (interpreted as .IR "unsigned char" ) that differ in .I s1 and .IR s2 . .P If .I n is zero, the return value is zero. .SH ATTRIBUTES For an explanation of the terms used in this section, see .BR attributes (7). .TS allbox; lbx lb lb l l l. Interface Attribute Value T{ .na .nh .BR memcmp () T} Thread safety MT-Safe .TE .SH VERSIONS POSIX.1 specifies only that: .RS .P The sign of a nonzero return value shall be determined by the sign of the difference between the values of the first pair of bytes (both interpreted as type .IR "unsigned char" ) that differ in the strings being compared. .RE .P In glibc, as in most other implementations, the return value is the arithmetic result of subtracting the last compared byte in .I s2 from the last compared byte in .IR s1 . (If the two characters are equal, this difference is 0.) .SH STANDARDS C11, POSIX.1-2008. .SH HISTORY POSIX.1-2001, C89, SVr4, 4.3BSD. .SH CAVEATS Do not use .BR memcmp () to compare confidential data, such as cryptographic secrets, because the CPU time required for the comparison depends on the contents of the addresses compared, this function is subject to timing-based side-channel attacks. In such cases, a function that performs comparisons in deterministic time, depending only on .I n (the quantity of bytes compared) is required. Some operating systems provide such a function (e.g., NetBSD's .BR consttime_memequal ()), but no such function is specified in POSIX. On Linux, you may need to implement such a function yourself. .SH SEE ALSO .BR memory.h (3head), .BR memeq (3), .BR wmemcmp (3)