b75822bc6e
On deallocation, sampled pointers (specially aligned) get junked and stashed into tcache (to prevent immediate reuse). The expected behavior is to have read-after-free corrupted and stopped by the junk-filling, while write-after-free is checked when flushing the stashed pointers.
4 lines
52 B
Bash
4 lines
52 B
Bash
#!/bin/sh
|
|
|
|
export MALLOC_CONF="lg_san_uaf_align:12"
|