[Bug analyzer/126832] New: false -Wanalyzer-malloc-leak failing to track pointer identity through linked-list store/load

"dmalcolm at gcc dot gnu.org via Gcc-bugs" <[email protected]>
Newsgroups gmane.comp.gcc.bugs
Message-ID <[email protected]/bugzilla/>
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=126832

            Bug ID: 126832
           Summary: false -Wanalyzer-malloc-leak failing to track pointer
                    identity through linked-list store/load
           Product: gcc
           Version: 17.0
            Status: UNCONFIRMED
          Severity: normal
          Priority: P3
         Component: analyzer
          Assignee: dmalcolm at gcc dot gnu.org
          Reporter: dmalcolm at gcc dot gnu.org
            Blocks: 126830
  Target Milestone: ---

Reduced from erofs-utils-1.9.3 erofs_iput().

After inserting a malloc'd struct into an intrusive linked list via its
embedded
list_head, freeing via head.next should free the struct (since the link field
is
at offset 0).  The analyzer can't track the identity through the store/load
chain.

$ cat t.c
typedef __SIZE_TYPE__ size_t;
extern void free(void *);
extern void *malloc(size_t);

struct list_head {
    struct list_head *prev;
    struct list_head *next;
};

struct item {
    struct list_head link;
    int data;
};

void test(void) {
    struct list_head head;
    struct item *a;

    head.prev = &head;
    head.next = &head;

    a = (struct item *)malloc(sizeof(*a));
    if (!a) return;

    a->link.prev = head.prev;
    a->link.next = &head;
    head.prev->next = &a->link;
    head.prev = &a->link;

    free(head.next); /* bogus leak of 'a' */
}

$ gcc -fanalyzer -c t.c
t.c: In function 'test':
t.c:30:1: warning: leak of 'a' [CWE-401] [-Wanalyzer-malloc-leak]

Trunk: https://godbolt.org/z/94EW36T3n

Seen in the August 2026 OpenScanHub mass scan of Fedora 45 (PR 126830) as the
dominant FP pattern in kernel code (list_for_each_entry / container_of), also
affecting erofs-utils, mesa, nftables, pipewire, firefox, and others
(est. 1,500-2,000 FPs).


Referenced Bugs:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=126830
[Bug 126830] Tracker bug for -fanalyzer false positives seen in August 2026
OpenScanHub mass scan
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.