[C++] Alias analysis failure on pointer to local variable
- Lingua principale
- CodeQL
- Stelle
- 10.1k
- Fork
- 2.1k
- Merge medio
- 2g 15h
- PR unite (30g)
- 141
Descrizione
Assigning to a local variable though a pointer appears to defeat the taint tracking. In the following example I would have expected to see a taint flow from line 16 to 17 but only the one from line 19 to 20 is reported. The taint seems to not propagate through the pointer correctly.
```cpp
int source()
{
return 2;
}
int target(int source)
{
return source;
}
int main(int argv, char **argc)
{
int a;
int *c = &a;
*c = source();
target(a); // not detected as reached
a = source();
target(a); // detected as reached
return 0;
}
```
This is the query I ran.
```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking
module SourceSinkCallConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source.asExpr().(Call).getTarget().getName() = "source"
}
predicate isSink(DataFlow::Node sink) {
exists(Call call |
call.getTarget().getName() = "target" and
call.getArgument(0) = sink.asExpr()
)
}
}
module SourceSinkCallTaint = TaintTracking::Global;
from DataFlow::Node source, DataFlow::Node sink, int source_line, int sink_line
where
SourceSinkCallTaint::flow(source, sink) and
source_line = source.getLocation().getStartLine() and
sink_line = sink.getLocation().getStartLine()
select source, source_line, sink, sink_line
```
This is the output I received.
```
| source | source_line | sink | sink_line |
+----------------+-------------+------+-----------+
| call to source | 19 | a | 20 |
```
CodeQL version: 2.19.3
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Inizia eseguendo il reproducer C++ fornito e la query SourceSinkCallTaint con CodeQL 2.19.3, quindi traccia il comportamento del taint tracking di C++ per le scritture tramite puntatori e le variabili locali. Il lavoro è completato quando viene segnalato il flusso dalla riga 16 alla riga 17 insieme al flusso esistente dalla riga 19 alla riga 20.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- cpp
- Ambito
- devtools, security
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100