Detecting Memory-Related Bugs by Tracking Heap Memory Management of C++ Smart Pointers
Xutong Ma, Jiwei Yan, Wei Wang, Jun Yan, Jian Zhang, Zongyan Qiu
Abstract
The smart pointer mechanism, which is improved in the continuous versions of the C++ standards over the last decade, is designed to prevent memory-leak bugs by automatically deallocating the managed memory blocks. However, not all kinds of memory errors can be immunized by adopting this mechanism. For example, dereferencing a null smart pointer will lead to a software failure. Due to the lack of specialized support for smart pointers, the off-the-shelf C++ static analyzers cannot effectively reveal these bugs. In this paper, we propose a static approach to detecting memory-related bugs by tracking the heap memory management of smart pointers. The behaviors of smart pointers are modeled during their lifetime to trace the state transitions of managed memory blocks. And the specially designed checkers are used to check the state changes according to five collected bug patterns. To evaluate the effectiveness of our approach, we implement it on the top of the Clang Static Analyzer. A set of handmade code snippets, as well as nine popular open-source C++ projects, are used to compare our tool against four other analyzers. The results show that our approach can successfully discover nearly all the built-in bugs. And 442 out of 648 reports generated from the open-source projects are true positives after manual reviewing, where the bugs of dereferencing null smart pointers are most frequently reported. To further confirm our reports, we design patches for Aria2, Restbed, MySQL and LLVM, in which seven pull requests covering 76 bug reports have been merged by the developers up to now. The results indicate that pointers should always be carefully used even after migrated to smart pointers and static analysis upon specialized models can effectively detect such bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19ef1751-77e8-492e-882e-99ff4b98cd52Cited by top-tier papers2
- Detecting Memory Errors in Python Native Code by Tracking Object Lifecycle with Reference CountXutong Ma, Jiwei Yan, Hao Zhang, Jun Yan et al.ASE 2023 · 2 citations
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu et al.ASE 2025
Builds on3
- SAVER: scalable, precise, and safe memory-error repairSeongjoon Hong, Junhee Lee, Jeongsoo Lee, Hakjoo OhICSE 2020 · 28 citations
- Past-sensitive pointer analysis for symbolic executionDavid Trabish, Timotej Kapus, Noam Rinetzky, Cristian CadarFSE 2020 · 9 citations
- Tailoring programs for static analysis via program transformationRijnard van Tonder, Claire Le GouesICSE 2020 · 6 citations
Related papers
- Evaluating the Effectiveness of Memory Safety SanitizersEmanuel Q. Vintila, Philipp Zieris, Julian HorschS&P 2025
- On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer ExceptionsDavid A. Tomassi, Cindy Rubio-GonzálezASE 2021 · 24 citations
- Detecting API Post-Handling Bugs Using Code and Description in PatchesMiaoqian Lin, Kai Chen, Yang XiaoUSENIX Security 2023
- Detecting Exception Handling Bugs in C++ ProgramsHao Zhang, Ji Luo, Mengze Hu, Jun Yan et al.ICSE 2023 · 7 citations
- BESA: Extending Bugs Triggered by Runtime Testing via Static AnalysisJia-Ju BaiEuroSys 2025 · 1 citation
