Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On Linux with glibc, malloc() returns a pointer in the process’s virtual address space; it does not hand the program a physical RAM address or guarantee that every requested byte is already resident in RAM. The allocator manages the request, the kernel sets up or expands address-space mappings, and the CPU’s memory-management unit (MMU) translates virtual addresses when the program accesses them. A page fault may ask the kernel to resolve an access, but it does not necessarily mean a disk read.

What actually happens when I call malloc()?

The C library’s malloc(size) function requests uninitialized storage for size bytes and returns a pointer or reports failure. The C interface does not prescribe how Linux obtains that storage. On Linux with glibc, the allocator may reuse a suitable free block it already manages. If it needs more address space, it commonly grows the heap with brk() or obtains a private anonymous mapping with mmap().

The choice is an allocator implementation detail, not a promise that a particular request always follows one path. Linux man-pages documents a default glibc MMAP_THRESHOLD of 128 kB for using mmap() for large allocations, and says the threshold is adjustable with mallopt(). Treat that figure as a configurable default—not a fixed cutoff: allocator state, arenas, tunings, and versions can affect the route. See the malloc(3) documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Allocation and mapping are different jobs

malloc() is the library allocator’s interface to your program. A system call such as brk() or mmap() is one way the allocator can obtain or manage address space from the operating system. A mapping records a relationship between a range of virtual addresses and backing; it does not by itself mean that every page in that range has a physical frame resident immediately. Linux’s mmap(2) documentation describes mapping behavior and flags.

Does malloc() allocate physical memory?

Not directly. The pointer returned by malloc() is a virtual address meaningful within that process. Physical memory is organized in page frames, and the kernel maintains the mappings that connect virtual pages to physical frames when needed. The MMU uses those mappings to translate addresses as the CPU accesses memory; it does not decide how malloc() satisfies an allocation.

Linux’s page-table overview explains that the kernel establishes and maintains page-table structures while the MMU performs virtual-to-physical translation. Hardware translation caches can speed up repeated translations. The hierarchy’s depth and other implementation details depend on the processor architecture, so the useful model is the division of responsibility rather than one particular page-table layout. See the Linux kernel’s Page Tables documentation for version 6.10.

Think of malloc() as giving the program an address in its own numbered map. The kernel maintains the map, and the MMU consults it to reach physical locations. This is only an analogy: real mappings also involve permissions, translation caches, shared pages, and different backing policies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does the memory profiler show less RAM than I allocated?

Because “bytes requested from malloc()” and “bytes currently resident in physical memory” describe different things. An allocator can reserve or manage a virtual range without every page in it being resident. With demand paging, physical backing may be established as the program accesses pages rather than all at once when it requests an allocation.

So, if a profiler’s RAM figure represents resident memory, it can be lower than the total size of outstanding allocations when some allocated pages have not been touched. The difference does not by itself mean that malloc() ignored the request or that the memory is missing; it reflects the distinction between virtual allocation and present residency. What a particular profiler counts depends on its metric.

What happens when I touch a page for the first time?

  1. The program issues a load or store. It uses the virtual address returned by malloc(), often at an offset within the allocated range.
  2. The MMU checks the translation. It uses the active page tables, with hardware translation caches helping when a translation is already available.
  3. If the access cannot proceed, the processor raises a page-fault exception. Control transfers to the kernel. The fault is a request to resolve or reject this access, not a statement about what storage device must be involved.
  4. The kernel checks the address and operation. If the address is valid and the operation is allowed, the kernel resolves the mapping as appropriate—for example, by establishing anonymous-memory backing, loading file-backed contents, or bringing a swapped-out page back.
  5. The instruction resumes if resolution succeeds. With the mapping and translation state available, the CPU can complete the access to the relevant physical page frame. If the address is invalid or the operation is prohibited, the process may instead receive a signal such as SIGSEGV.

A virtual address does not promise a unique physical location that is permanently reserved from the moment of allocation. Pages can be shared or reclaimed, and mapping and backing details vary. The Linux kernel’s page-table overview describes fault handling at a high level; exact behavior depends on the mapping and platform.

Does every page fault mean disk access?

No. A page fault is an exception that gives the kernel a chance to check and resolve an access. If an anonymous page needs backing, the kernel may establish it without reading the page’s contents from disk. A file-backed page may need to be fetched from storage, and a swapped-out page may need to be brought back from swap. An invalid or disallowed access may fail rather than load anything.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The backing type matters. The GNU C Library manual describes not-yet-loaded pages in file mappings as being handled similarly to swapped-out pages. That does not make every fault a disk read: whether I/O is needed depends on why the access faulted and what backing the mapping has. See the glibc manual’s section on memory-mapped I/O.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why can malloc() succeed before all memory is available?

Linux generally uses optimistic memory allocation. As the malloc(3) man page puts it, “By default, Linux follows an optimistic memory allocation strategy.” A non-NULL result means the allocator accepted the request; it is not proof that all requested pages are resident or that the system can ultimately provide backing for every later access. Memory pressure and system policy can matter after allocation.

For broader study of address spaces, paging, page tables, and memory APIs, Operating Systems: Three Easy Pieces offers free online chapters alongside information about the book.

Which parts of this explanation are Linux- and glibc-specific?

The allocator paths and the documented 128 kB default threshold here are about Linux with glibc, as described by Linux man-pages documentation reported on 2026-02-08. Other C libraries, allocators, operating systems, tunables, and versions can behave differently. The mapping interface is broader than Linux, but flags and behavior can be implementation-specific; see the POSIX mmap(3p) manual for the POSIX interface. The page-table explanation is a high-level overview from Linux kernel documentation version 6.10, not a specification of every processor’s page-table format.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.