github / github/codeql

False Positive: cpp/use-after-free on chained assignment after delete

オープン
#21,187 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
false-positive
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**

I have encountered a false positive with the rule cpp/use-after-free.
CodeQL incorrectly flags a variable as being "used after free" when it is assigned via a chained assignment immediately following a delete[].
The analyzer seems to propagate the "freed" state of the dereferenced pointer to the local variable, failing to recognize that the new operator in the right-hand side of the assignment refreshes the pointer before the local variable reads it.

**Code samples or links to source code**
```
#include

void reallocateBuffer(char** sharedPtr, int size) {
// 1. Memory is freed
delete[] *sharedPtr;

char* localPtr;

// 2. Chained assignment:
// C++ guarantees right-to-left associativity.
// 'new' happens first, updates '*sharedPtr', and THEN 'localPtr' takes that value.
localPtr = *sharedPtr = new char[size];

// 3. CodeQL flags 'localPtr' as Use-After-Free here
if (localPtr) {
localPtr[0] = 'A';
}
}

int main() {
char* data = new char[10];
reallocateBuffer(&data, 50);
delete[] data;
return 0;
}
```

**Expected Behavior**

CodeQL should recognize that localPtr is assigned the result of the new allocation (via *sharedPtr) and is therefore safe to use.

**Actual Behavior**

CodeQL reports cpp/use-after-free on the line localPtr[0] = 'A';, claiming localPtr points to memory that was freed by delete[] *sharedPtr.

**Query / Rule ID**
cpp/use-after-free

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the cpp/use-after-free query named in the issue and use the supplied C++ reproducer to trace the report on the chained assignment. Done means the analyzer no longer reports localPtr[0] as a use-after-free while continuing to detect genuine cases.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
cpp
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。