Checked C
kristerw.blogspot.com
kristerw.blogspot.com
Also: "either (1) the operation must convert that value to an in-range integer value or (2) the expression shall produce a runtime error"
Is more defined, but does not actually help you much, because this will depend on platforms, and a overflow to 0 might produce similar issues when indexing as other errors today in creating bugs in encryption algorithms.
If we all agree that C is not a safe language, and that we'd all prefer writing in a safe language, then why not write in a safe language, e.g. Rust.
An aside: I've recently done a project where I explored replacing C library functions with Rust implementations, linking in the Rust library directly to the existing C library. I was very pleasantly surprised at the ease of doing this! This means that we really can migrate away from C in an iterative fashion, just as Checked C would allow us to do.
http://oirase.annexia.org/bounds/
Original was a MS Word 6 document (!)
It's sort of halfway between C and C++, with constructs like
array_ptr<T>