Use-after-Free
Also known as:UAF
Use-after-Free: Access to memory that has already been freed and possibly reallocated. The vulnerability class is among the most common forms of memory corruptionMemory CorruptionUnintentional or targeted alteration of storage structures with security implications. in C and C++ programs.
How it works and where it fits
After a free() the pointer to the region often remains, even though the allocator has released the block for reuse. If the program later dereferences it, it reads or writes memory that now belongs to a different object. An attacker deliberately places a crafted structure there — with modern allocators via the tcache, for example — and thereby controls fields the program treats as trustworthy. If one of those fields points to a function, the memory error becomes code execution.
Practical security relevance
Use-after-free rarely stems from a single wrong line but from inconsistent responsibility for object lifetimes, often aggravated by concurrency. Effective countermeasures address the cause: consistently nulling pointers after free, ownership models as in Rust, hardened allocators with delayed reuse, and memory sanitizers during testing. For assessment, the decisive question is whether the attacker can reliably influence what occupies the freed block.
Related concepts
- Memory CorruptionMemory CorruptionUnintentional or targeted alteration of storage structures with security implications.: Unintentional or targeted alteration of storage structures with security implications.
- Buffer OverflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data.: Writing beyond the bounds of a memory buffer, overwriting adjacent data.
- Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.
- Secure CodingSecure CodingProgramming practices aimed at avoiding common vulnerabilities and misconfigurations.: Programming practices aimed at avoiding common vulnerabilities and misconfigurations.