mallopt(M_PERTURB) does not perturbates the memory when free
05:31 11 Nov 2025

I am trying to catch memory-related bugs such as use-after-free by mallopt(M_PERTURB, ). According to the doc, the memory will be initialized to value when it has been released by free.

However, I cannot observe this effect. Consider the following code:

#include 
#include 
#include 
#include 
#include 

int main()
{
    mallopt(M_PERTURB, 0x33);
    uint64_t *ptr = malloc(32);
    if (!ptr) {
        return -1;
    }
    printf("%016lx\n", ptr[0]);  // cccccccccccccccc
    memset(ptr, 0, 32);
    printf("%016lx\n", ptr[0]);  // 0000000000000000

    free(ptr);
    printf("%016lx\n", ptr[0]);  // 0000000564dfa8b0

    return 0;
}

It did initialize memory to all 0xcc after malloc, but failed to do so in free. Is there something that I am missing? Or is it a bug of glibc?

gcc version: gcc (Debian 12.2.0-14) 12.2.0

c memory-management malloc glibc libc