Definition
Plain language
The pool of memory a running program uses for data whose size isn't known in advance.
As stated in the literature
The region of dynamically allocated process memory; corruption of heap allocations via use-after-free, double-free, or buffer overflow is the dominant memory-safety vulnerability class targeted in this corpus.
Also called: heap allocation
Why it matters: Mishandling this memory is the most common source of serious security holes, making it a prime target for both attackers and bug-finding tools.
For example, when a program loads an image whose size it learns only at runtime, it sets aside heap memory to hold the pixels.
Heard on the show
“… The method does five things: it reads a heap pointer from an object, it frees that pointer, it allocates a new buffer, it stores the new pointer …”Episode 024 — An AI Agent That Found 28 Zero-Days in Windows — And What Made It Work