@@ -3326,6 +3326,7 @@ _int_malloc (mstate av, size_t bytes)
INTERNAL_SIZE_T size; /* its size */
int victim_index; /* its bin index */
+ mchunkptr next; /* next contiguous chunk */
mchunkptr remainder; /* remainder from a split */
unsigned long remainder_size; /* its size */
@@ -3470,12 +3471,38 @@ _int_malloc (mstate av, size_t bytes)
while ((victim = unsorted_chunks (av)->bk) != unsorted_chunks (av))
{
bck = victim->bk;
- if (__builtin_expect (chunksize_nomask (victim) <= 2 * SIZE_SZ, 0)
- || __builtin_expect (chunksize_nomask (victim)
- > av->system_mem, 0))
- malloc_printerr (check_action, "malloc(): memory corruption",
- chunk2mem (victim), av);
size = chunksize (victim);
+ next = chunk_at_offset (victim, size);
+
+ if (__glibc_unlikely (chunksize_nomask (victim) <= 2 * SIZE_SZ)
+ || __glibc_unlikely (chunksize_nomask (victim) > av->system_mem))
+ {
+ errstr = "malloc(): invalid size (unsorted)";
+ goto errout;
+ }
+ if (__glibc_unlikely (chunksize_nomask (next) < 2 * SIZE_SZ)
+ || __glibc_unlikely (chunksize_nomask (next) > av->system_mem))
+ {
+ errstr = "malloc(): invalid next size (unsorted)";
+ goto errout;
+ }
+ if (__glibc_unlikely ((prev_size (next) & ~(SIZE_BITS)) != size))
+ {
+ errstr = "malloc(): mismatching next->prev_size (unsorted)";
+ goto errout;
+ }
+ if (__glibc_unlikely (bck->fd != victim)
+ || __glibc_unlikely (victim->fd != unsorted_chunks (av)))
+ {
+ errstr = "malloc(): unsorted double linked list corrupted";
+ goto errout;
+ }
+ if (__glibc_unlikely (prev_inuse(next)))
+ {
+ errstr = "malloc(): invalid next->prev_inuse (unsorted)";
+ goto errout;
+ }
+
/*
If a small request, try to use last remainder if it is the