github / github/codeql

False positives in cpp/use-after-free

未關閉
#15,676 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
C++ false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I'm getting about 20 of these on my code but I'll only show one because they're all the same.

CodeQL is identifying this as a potential use after free because there's a `delete[]` on line 3 of this sample. But line 5 calls `new[]` so the pointer used on line 6 should never be dangerous to use. I don't know if CodeQL is confused by the number of pointers but this isn't an issue.

Step 1 pointer to operator delete[] output argument
Step 2 *m_CSEngine [post update] [m_arrSpeedInit]
Step 3 *m_pRaw [post update] [*m_CSEngine, m_arrSpeedInit]
Step 4 *this [post update] [*m_pRaw, *m_CSEngine, m_arrSpeedInit]
Step 5 *this [*m_pRaw, *m_CSEngine, m_arrSpeedInit]
Step 6 *m_pRaw [*m_CSEngine, m_arrSpeedInit]
Step 7 *m_CSEngine [m_arrSpeedInit]
Step 8 m_arrSpeedInit - Memory may have been previously freed by delete[].

```
if (((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_arrSpeedInit!=NULL)
{
delete []((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_arrSpeedInit; // <- Steps 1, 2, 3, 4
}
((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_arrSpeedInit = new int[((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_numberObj];
memcpy(((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_arrSpeedInit,(BYTE*)p+pos,((CRawDetectionPlate*)m_pRaw)->m_CSEngine->m_numberObj*sizeof(int)); // <- Steps 5, 6, 7, 8
```

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。