github / github/codeql

FP in UseAfterFree with reallocating data structures

未關閉
#20,577 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
C++ false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

UseAfterFree.ql raises a false positive when run on a data structure with reallocated internal storage. I've observed with in several different data structure implementations, but the example below triggers the FP.

```cpp
typedef unsigned long long size_t;

template class Foo {
public:
Foo(void): capacity(0), size(0), items(nullptr) {}

~Foo(void) { Clear(); }

void Clear(void) {
if (items != nullptr) {
delete[] items;
items = nullptr;
size = 0;
capacity = 0;
}
}

T *Set(size_t index, T *item) {
if (index >= capacity) {
size_t new_capacity = capacity == 0 ? 4 : capacity;
while (index >= new_capacity) {
new_capacity *= 2;
}
T **new_items = new T *[new_capacity];
for (size_t i = 0; i < size; i++) {
new_items[i] = items[i];
}
if (items != nullptr) {
delete[] items;
}
items = new_items;
capacity = new_capacity;
}

if (index >= size) {
for (size_t i = size; i < index; i++) {
items[i] = nullptr;
}
size = index + 1;
}

items[index] = item;
return item;
}

T *Insert(size_t index, T *item) {
for (size_t i = index; i < size; i++) {
if (Set(i + 1, Get(i))) {
return nullptr;
}
}
return Set(index, item);
}

T *Get(size_t index) {
if (size <= index) {
return nullptr;
}
return items[index];
}

protected:
size_t capacity;
size_t size;
T **items;
};

int main() {
Foo foo;
foo.Set(1024, new size_t(44));
foo.Clear();
foo.Insert(1025, new size_t(46));
foo.Get(1025);
return 0;
}
```

To save anyone else the effort, this does not actually have a UAF exercised according to ASAN :)

貢獻指南

開啟貢獻指南

研究方向

Start by locating UseAfterFree.ql and reproducing the supplied C++ example to inspect why the reallocating data structure is reported. Compare the result with ASAN, then verify that the example is no longer flagged while genuine use-after-free cases remain detected.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
cpp
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。