[Bug c/126768] New: ASAN -fsanitize-address-use-after-scope incomplete

cs at aibiot dot de via Gcc-bugs <[email protected]>
Newsgroups gmane.comp.gcc.bugs
Message-ID <[email protected]/bugzilla/>
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=126768

            Bug ID: 126768
           Summary: ASAN -fsanitize-address-use-after-scope incomplete
           Product: gcc
           Version: 16.2.0
            Status: UNCONFIRMED
          Severity: normal
          Priority: P3
         Component: c
          Assignee: unassigned at gcc dot gnu.org
          Reporter: cs at aibiot dot de
  Target Milestone: ---

This code:

#include <stdio.h>
#include <stdlib.h>

void * test () {
    void * ret = alloca (1024);
    snprintf (ret, 1024, "use after free");
    return ret;
}

int main () {
    void * ret = test ();
    puts (ret);
}

When compiled with

-g -std=c23 -D _DEFAULT_SOURCE -Og -Wall -Werror -Wextra -Wpedantic -Wshadow
-pipe -flto=auto -fPIC -fsanitize=address -fsanitize-address-use-after-scope -c
-o test.o test.c

linked with

-g -std=c23 -D _DEFAULT_SOURCE -Og -Wall -Werror -Wextra -Wpedantic -Wshadow
-pipe -flto=auto -fPIC -fsanitize=address -fsanitize-address-use-after-scope
-static-libasan  -o test test.o 

and run with
ASAN_OPTIONS =
strict_string_checks=1:detect_stack_use_after_return=1:check_initialization_order=1:strict_init_order=1
./test

(unexpectedly) works with gcc 16.2.0, but (expectedly) fails with clang 22.1.8:
=================================================================
==1690372==ERROR: AddressSanitizer: stack-use-after-scope on address
0x7b1ebedf0020 at pc 0x55a2b3c51fd7 bp 0x7ffd1d9ff2d0 sp 0x7ffd1d9feaa0

It however works with a static allocation:

void * test () {
    char buf[1024];
    void * ret = buf;
    snprintf (ret, 1024, "use after free");
    return ret;
}
=================================================================
==1693457==ERROR: AddressSanitizer: stack-use-after-return on address
0x7bde0b3f0020 at pc 0x55ce02b88b82 bp 0x7ffefa83c770 sp 0x7ffefa83bf18

I understand that the use of alloca() is discouraged, but neither does gcc
detect the use-after-free during static analysis as it does with a
malloc()/free() pair, nor does its ASAN implementation catch the use.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.