Glossary
tcache (thread cache)
A per-thread cache of freed heap chunks in glibc 2.26+ that speeds small allocations, and a common target of heap-exploitation techniques.
The tcache (thread cache) is a per-thread set of singly linked free lists that glibc 2.26 and later use to serve small allocations quickly. A freed chunk stores the pointer to the next free chunk (fd) in its own body, and malloc returns whatever the list head points to.
That design makes the tcache a frequent target: a use-after-free or double free that overwrites a freed chunk's fd lets an attacker control where the next allocation is placed — a powerful write primitive. glibc later added a double-free key (2.29) and safe-linking (2.32), which XORs the fd with a heap-derived secret, forcing an attacker to leak a heap address first. See heap exploitation with tcache and use-after-free.