Mismatched allocation and deallocation

Memory released with a mismatched allocator family

Description

Using a deallocation function that does not match the allocator can cause a vulnerability. Examples include releasing an array allocated with new[] using delete, or releasing a kernel pool allocation with ordinary free.

Potential impact

  • Corrupted heap or pool metadata can cause crashes.
  • Destructors may not run correctly, causing resource leaks or undefined behavior.

Remediation

  1. Release malloc-family allocations with free.
  2. Pair new with delete, and new[] with delete[].
  3. Use the matching release API for platform-specific or kernel allocations.

Examples

Before

cpp
void run() {
    int *items = new int[16];
    delete items;
}

After

cpp
void run() {
    int *items = new int[16];
    delete[] items;
}

Explanation:

  • Before: delete does not match the array allocation.
  • After: delete[] matches the allocation made with new[].

References