Skip to content

validate arg indirect attribute before indexing direction array - #8850

Open
Nussu06 wants to merge 2 commits into
cppcheck-opensource:mainfrom
Nussu06:library-indirect-bounds
Open

Nussu06 wants to merge 2 commits into
cppcheck-opensource:mainfrom
Nussu06:library-indirect-bounds

Conversation

@Nussu06

@Nussu06 Nussu06 commented Sep 13, 2026

Copy link
Copy Markdown

loadFunction writes ac.direction[indirect] where indirect comes straight from the indirect attribute of an <arg> element in a --library cfg file, with no range check, so a value like indirect="1000000" or indirect="-5" writes outside the fixed 3-element direction array. Reject an out-of-range indirect with BAD_ATTRIBUTE_VALUE, matching the bounds check getArgDirection already applies when reading the same array.

Comment thread lib/library.cpp
}
if (const char* const argIndirect = functionnode->Attribute("indirect")) {
const int indirect = strToInt<int>(argIndirect);
if (indirect < 0 || indirect >= static_cast<int>(ac.direction.size()))

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please suppress this

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The alert on this line is premium-cert-int31-c (I checked the SARIF from the PR's premium run), and that id is in cppcheckpremium-suppressions on main since #8915. An inline suppression would be redundant with that, so I merged main into the branch instead, which lets the Premium job pick up the updated list. No change to the diff itself. The workflow runs for the new push are waiting for approval, so I can't confirm the job is green yet. If you'd still prefer an inline cppcheck-suppress here, I'll add it.

Comment thread lib/library.cpp
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants