github / github/codeql

[C++] Alias analysis failure on pointer to local variable

Đang mở
#18,101 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

Assigning to a local variable though a pointer appears to defeat the taint tracking. In the following example I would have expected to see a taint flow from line 16 to 17 but only the one from line 19 to 20 is reported. The taint seems to not propagate through the pointer correctly.

```cpp
int source()
{
return 2;
}

int target(int source)
{
return source;
}
int main(int argv, char **argc)
{
int a;
int *c = &a;
*c = source();
target(a); // not detected as reached

a = source();
target(a); // detected as reached

return 0;
}
```

This is the query I ran.

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module SourceSinkCallConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source.asExpr().(Call).getTarget().getName() = "source"
}

predicate isSink(DataFlow::Node sink) {
exists(Call call |
call.getTarget().getName() = "target" and
call.getArgument(0) = sink.asExpr()
)
}
}

module SourceSinkCallTaint = TaintTracking::Global;

from DataFlow::Node source, DataFlow::Node sink, int source_line, int sink_line
where
SourceSinkCallTaint::flow(source, sink) and
source_line = source.getLocation().getStartLine() and
sink_line = sink.getLocation().getStartLine()
select source, source_line, sink, sink_line
```

This is the output I received.

```
| source | source_line | sink | sink_line |
+----------------+-------------+------+-----------+
| call to source | 19 | a | 20 |
```

CodeQL version: 2.19.3

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.