malloc is special in environments that aren't free-standing, the compiler can assume that the pointer that malloc returns doesn't alias any other at that point.
C11 4 [conformance]/p6 "A conforming freestanding implementation shall accept any strictly conforming program in which the use of the features specified in the library clause (clause 7) is confined to the contents of the standard headers <float.h>, <iso646.h>, <limits.h>, <stdalign.h>, <stdarg.h>, <stdbool.h>, <stddef.h>, <stdint.h>, and <stdnoreturn.h>." [2]
[1] http://www.open-std.org/jtc1/sc22/wg21/docs/papers/2011/n324... [2] http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1570.pdf