github / github/codeql

C++: Return statement inside Guard Block

Open
#15,001 5 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Is the dataFlow guarded if the condition has return statement?
Here's the code
```
#include
#include

bool test_func(const char* str1, const char* str2) {
return strcmp(str1, str2) == 0;
}

struct test_struct {
int a;
int b;
};

int func(int num){
struct test_struct *test = NULL;
if(num > 0) {
test = (test_struct *)calloc(num, sizeof(*test));
if(!test) {
return 1;
}
}

test[0].a = 1;
test[0].b = 2;
return 0;
}
int main() {
func(2);
func(0);
return 0;
}
```

Here's the query

```
/**
* @kind path-problem
*/

import cpp
import semmle.code.cpp.dataflow.new.DataFlow
import semmle.code.cpp.controlflow.IRGuards
import Flow::PathGraph

/**
* Holds if `g` is a guard that ensures that `e` is not null when `g` evaluates to `branch`
*/
predicate isNotNullCheck(IRGuardCondition g, Expr e, boolean branch) {
g.comparesEq(any(Instruction instr | instr.getUnconvertedResultExpression() = e).getAUse(),
any(ConstantValueInstruction const | const.getValue() = "0").getAUse(), 0, false, branch)
}

module UAFConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(Expr e | e = source.asExpr() | e.(NullValue).getValue().toInt() = 0)

}

predicate isSink(DataFlow::Node sink) {
dereferenced(sink.asExpr())
}

predicate isBarrier(DataFlow::Node node) {
node = DataFlow::BarrierGuard::getABarrierNode()
}
}

module Flow = DataFlow::Global;

from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink, source, sink, "Null ptr deref: $@ and $@.", source, "source", sink, "deref"
```

Output:
1.test=NULL, -> test[0].a , this is TP
2. calloc() , -> test[0].a , this is FP because when calloc return null, test[0] is unreachable..
two more results for test[1], which is same as above..

Is this because Guard Condition can't see the return statement inside the conditional block?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.