Double free

Double free

Description

Freeing the same memory region twice can corrupt allocator state.

Potential impact

  • Crashes, use-after-free, or arbitrary code execution may result.

Remediation

Manage ownership through a single path. Clear the pointer after freeing memory, or use RAII.

Examples

Before

c
char *p = malloc(16);
free(p);
free(p);

After

c
char *p = malloc(16);
free(p);
p = NULL;

Explanation:

  • Before: The same pointer is freed twice in succession.
  • After: The pointer is cleared after freeing the allocation so it no longer refers to the freed memory.

References