Dereferencing a pointer after memory pointed to has been deallocated with free().
Occurs when code accesses memory through a pointer after `free(ptr)` has already returned that memory block back to the heap allocator.
Keeping stale pointer references in multiple struct fields or local variables after deallocating the underlying memory allocation.
1#include <stdio.h>2#include <stdlib.h>3 4int main() {5 int *data = malloc(sizeof(int));6 *data = 100;7 8 free(data); // Memory freed9 10 // Bug: Reading dangling pointer!11 printf("Value: %d\n", *data); // Use-After-Free undefined behavior12 return 0;13}1#include <stdio.h>2#include <stdlib.h>3 4int main() {5 int *data = malloc(sizeof(int));6 if (data != NULL) {7 *data = 100;8 printf("Value: %d\n", *data);9 10 free(data);11 data = NULL; // Fix: Set pointer to NULL after freeing12 }13 return 0;14}Simulate standard system builds to trigger compiler trace records and track memory crashes locally.
After `free(data)`, the memory address pointed to by `data` is marked unallocated and can be reassigned by the OS. Dereferencing `*data` causes undefined behavior or crashes.