C++: Return statement inside Guard Block
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.1k
- Forks
- 2.1k
- Ø Merge
- 2 T. 15 Std.
- Gemergte PRs (30 T.)
- 141
Beschreibung
Is the dataFlow guarded if the condition has return statement?
Here's the code
```
#include
#include
bool test_func(const char* str1, const char* str2) {
return strcmp(str1, str2) == 0;
}
struct test_struct {
int a;
int b;
};
int func(int num){
struct test_struct *test = NULL;
if(num > 0) {
test = (test_struct *)calloc(num, sizeof(*test));
if(!test) {
return 1;
}
}
test[0].a = 1;
test[0].b = 2;
return 0;
}
int main() {
func(2);
func(0);
return 0;
}
```
Here's the query
```
/**
* @kind path-problem
*/
import cpp
import semmle.code.cpp.dataflow.new.DataFlow
import semmle.code.cpp.controlflow.IRGuards
import Flow::PathGraph
/**
* Holds if `g` is a guard that ensures that `e` is not null when `g` evaluates to `branch`
*/
predicate isNotNullCheck(IRGuardCondition g, Expr e, boolean branch) {
g.comparesEq(any(Instruction instr | instr.getUnconvertedResultExpression() = e).getAUse(),
any(ConstantValueInstruction const | const.getValue() = "0").getAUse(), 0, false, branch)
}
module UAFConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(Expr e | e = source.asExpr() | e.(NullValue).getValue().toInt() = 0)
}
predicate isSink(DataFlow::Node sink) {
dereferenced(sink.asExpr())
}
predicate isBarrier(DataFlow::Node node) {
node = DataFlow::BarrierGuard::getABarrierNode()
}
}
module Flow = DataFlow::Global;
from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink, source, sink, "Null ptr deref: $@ and $@.", source, "source", sink, "deref"
```
Output:
1.test=NULL, -> test[0].a , this is TP
2. calloc() , -> test[0].a , this is FP because when calloc return null, test[0] is unreachable..
two more results for test[1], which is same as above..
Is this because Guard Condition can't see the return statement inside the conditional block?
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.