I'm reading a textbook which describes defense that is be able to detect when a stack has been corrupted. The book says:
Recent versions of gcc incorporate a mechanism known as a stack protector into the generated code to detect buffer overruns. The idea is to store a special canary value in the stack frame between any local buffer and the rest of the stack state, as illustrated in the picture below:

This canary value, also referred to as aguard value, is generated randomly each time the program runs, and so there is no easy way for an attacker to determine what it is. Before restoring the register state and returning from the function, the program checks if the canary has been altered by some operation of this function or one that it has called. If so, the program aborts with an error.
I get the idea but I still think there is a flaw in this design. Yes the attacker might not be able to determine what the value of canary is, but the attacker know the size of canary(8 bytes), so the attacker can manipulate the pointer to bypass this 8 byte area in stack where canary locates then overwrite the return address, so canary actually protects nothing, is my understanding correct?