Remember, a large proportion of C code is for embedded/real-time systems where the only sensible recovery option is to reset.
Attempting to 'handle' an error manually in every case is simply not possible. Better to reset and come up in a clean state than propagate errors.
Having said that, dynamic memory allocation is itself frowned upon in embedded systems.
If we have a failure during rendezvous with our target, it could be a very bad day.
You always need to be able to recover from a soft reboot, even during maneuvers; you're in a high radiation environment and any passing high energy particle or cosmic ray can trigger this.
Any recommendations for reliable C data structures?
If that situation is not allowed, I would suggest you shouldn't be performing memory allocation (or any other resource allocation) dynamically.