CWE-401 — Missing Release of Memory after Effective Lifetime
CWE-401: Missing Release of Memory after Effective Lifetime
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Variant |
| Status | Draft |
| Likelihood of exploit | Medium |
Description
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Common consequences
- Availability: DoS: Crash, Exit, or Restart, DoS: Instability, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
- Other: Reduce Performance
Mitigations
Implementation — Choose a language or tool that provides automatic memory management, or makes manual memory management less error-prone. For example, glibc in Linux provides protection against free of invalid pointers. When using Xcode to target OS X or iOS, enable automatic reference counting (ARC) [REF-391]. To help correctly and consistently manage memory when programming in C++, consider using a smart pointer class such as std::auto_ptr (defined by ISO/IEC ISO/IEC 14882:2003), std::shared_ptr and std::unique_ptr (specified by an upcoming revision of the C++ standard, informally referred to as C++ 1x), or equivalent solutions such as Boost.
Architecture and Design — Use an abstraction library to abstract away risky APIs. Not a complete solution.
Architecture and Design — Consider using the Boehm-Demers-Weiser garbage collector (bdwgc), which can help avoid leaks.
References
- CWE page: https://cwe.mitre.org/data/definitions/401.html
- CWE list: https://cwe.mitre.org/data/index.html