github / github/codeql

C++: Return statement inside Guard Block

オープン
#15,001 コメント 5 件 リアクション 0 件 担当者 0 名 GitHub で見る
false-positive
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Is the dataFlow guarded if the condition has return statement?
Here's the code
```
#include
#include

bool test_func(const char* str1, const char* str2) {
return strcmp(str1, str2) == 0;
}

struct test_struct {
int a;
int b;
};

int func(int num){
struct test_struct *test = NULL;
if(num > 0) {
test = (test_struct *)calloc(num, sizeof(*test));
if(!test) {
return 1;
}
}

test[0].a = 1;
test[0].b = 2;
return 0;
}
int main() {
func(2);
func(0);
return 0;
}
```

Here's the query

```
/**
* @kind path-problem
*/

import cpp
import semmle.code.cpp.dataflow.new.DataFlow
import semmle.code.cpp.controlflow.IRGuards
import Flow::PathGraph

/**
* Holds if `g` is a guard that ensures that `e` is not null when `g` evaluates to `branch`
*/
predicate isNotNullCheck(IRGuardCondition g, Expr e, boolean branch) {
g.comparesEq(any(Instruction instr | instr.getUnconvertedResultExpression() = e).getAUse(),
any(ConstantValueInstruction const | const.getValue() = "0").getAUse(), 0, false, branch)
}

module UAFConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(Expr e | e = source.asExpr() | e.(NullValue).getValue().toInt() = 0)

}

predicate isSink(DataFlow::Node sink) {
dereferenced(sink.asExpr())
}

predicate isBarrier(DataFlow::Node node) {
node = DataFlow::BarrierGuard::getABarrierNode()
}
}

module Flow = DataFlow::Global;

from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink, source, sink, "Null ptr deref: $@ and $@.", source, "source", sink, "deref"
```

Output:
1.test=NULL, -> test[0].a , this is TP
2. calloc() , -> test[0].a , this is FP because when calloc return null, test[0] is unreachable..
two more results for test[1], which is same as above..

Is this because Guard Condition can't see the return statement inside the conditional block?

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。