mallopt with M_PERTURB option does not work as expected

David davidhu0903ex3@gmail.com
Wed Nov 12 17:25:59 GMT 2025


Hi,

We are trying to catch use-after-free bugs by enabling the `mallopt` with
the `M_PERTURB` parameter. However, to our surprise, when the memory to be
freed belongs to Tcache (aka sizes ranging from 1 to 1032), the call to
`free` simply won't perturb the memory as expected.
* From the library perspective, tcache is meant to be fast, so it decided
to skip the perturb process altogether.
* From the application perspective, it becomes hard to catch use-after-free
bugs, especially when most memory sizes are under 1032.
Therefore, I am asking if there is a compromise between the two
perspectives. Besides, maybe we should include the different behavior of
tcache in the man page
<https://man7.org/linux/man-pages/man3/mallopt.3.html>.

Thanks,
David


More information about the Libc-help mailing list