Description
Passing memory that was not dynamically allocated, a stack variable, or the address of a local object whose lifetime has ended to free, delete, or a kernel pool release function can cause invalid memory deallocation.
Potential impact
- Process crashes or kernel panics can cause denial of service.
- Corrupted heap metadata can lead to unpredictable behavior or security vulnerabilities.
Remediation
- Use
freefor memory allocated by themalloc,calloc, orreallocfamily. - Use
deleteonly for objects allocated withnew. - Do not pass addresses of stack or global variables to deallocation functions.
Examples
Before
c
void run(void) {
int value = 0;
int *p = &value;
free(p);
}
After
c
void run(void) {
int *p = malloc(sizeof(int));
if (p == NULL) {
return;
}
free(p);
}
Explanation:
- Before:
ppoints to the stack variablevalue, sofree(p)is invalid. - After:
ppoints to heap memory allocated withmallocand is released with the matchingfreefunction.