github / github/codeql

C++: Return statement inside Guard Block

Aperta
#15,001 5 commenti 0 reazioni 0 assegnatari Vedi su GitHub
false-positive
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

Is the dataFlow guarded if the condition has return statement?
Here's the code
```
#include
#include

bool test_func(const char* str1, const char* str2) {
return strcmp(str1, str2) == 0;
}

struct test_struct {
int a;
int b;
};

int func(int num){
struct test_struct *test = NULL;
if(num > 0) {
test = (test_struct *)calloc(num, sizeof(*test));
if(!test) {
return 1;
}
}

test[0].a = 1;
test[0].b = 2;
return 0;
}
int main() {
func(2);
func(0);
return 0;
}
```

Here's the query

```
/**
* @kind path-problem
*/

import cpp
import semmle.code.cpp.dataflow.new.DataFlow
import semmle.code.cpp.controlflow.IRGuards
import Flow::PathGraph

/**
* Holds if `g` is a guard that ensures that `e` is not null when `g` evaluates to `branch`
*/
predicate isNotNullCheck(IRGuardCondition g, Expr e, boolean branch) {
g.comparesEq(any(Instruction instr | instr.getUnconvertedResultExpression() = e).getAUse(),
any(ConstantValueInstruction const | const.getValue() = "0").getAUse(), 0, false, branch)
}

module UAFConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(Expr e | e = source.asExpr() | e.(NullValue).getValue().toInt() = 0)

}

predicate isSink(DataFlow::Node sink) {
dereferenced(sink.asExpr())
}

predicate isBarrier(DataFlow::Node node) {
node = DataFlow::BarrierGuard::getABarrierNode()
}
}

module Flow = DataFlow::Global;

from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink, source, sink, "Null ptr deref: $@ and $@.", source, "source", sink, "deref"
```

Output:
1.test=NULL, -> test[0].a , this is TP
2. calloc() , -> test[0].a , this is FP because when calloc return null, test[0] is unreachable..
two more results for test[1], which is same as above..

Is this because Guard Condition can't see the return statement inside the conditional block?

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.