Description
Using a deallocation function that does not match the allocator can cause a vulnerability. Examples include releasing an array allocated with new[] using delete, or releasing a kernel pool allocation with ordinary free.
Potential impact
- Corrupted heap or pool metadata can cause crashes.
- Destructors may not run correctly, causing resource leaks or undefined behavior.
Remediation
- Release
malloc-family allocations withfree. - Pair
newwithdelete, andnew[]withdelete[]. - Use the matching release API for platform-specific or kernel allocations.
Examples
Before
cpp
void run() {
int *items = new int[16];
delete items;
}
After
cpp
void run() {
int *items = new int[16];
delete[] items;
}
Explanation:
- Before:
deletedoes not match the array allocation. - After:
delete[]matches the allocation made withnew[].