Unchecked Return Value of Malloc Detection
Detection Workflow
- Identify allocation operations: Find all malloc() calls, locate calloc() calls, identify realloc() calls, map new/delete operations
- Trace return values: Follow allocation result, identify first dereference, check for NULL validation, assess error handling
- Check error handling: Verify NULL checks exist, assess error handling completeness, review fallback behavior, check for graceful degradation
- Assess impact: Can allocation fail? What happens on failure? Is crash possible? What's the security impact?
Key Patterns
- Unchecked malloc: malloc() return value not checked, direct use of malloc() result, no NULL check before dereference, assumption malloc never fails
- Unchecked calloc: calloc() return value not checked, direct use of calloc() result, no NULL check before dereference, assumption calloc never fails
- Unchecked realloc: realloc() return value not checked, direct assignment to original pointer, no NULL check before dereference, losing original pointer on failure
- Unchecked new (C++): new return value not checked, assuming new never throws, no exception handling, missing std::nothrow usage
Output Format
Report with: id, type, subtype, severity, confidence, location, vulnerability, allocation_call, allocation_type, allocation_size, null_check, first_dereference, exploitable, attack_scenario, impact, mitigation.
Severity Guidelines
- HIGH: Unchecked allocation in critical code
- MEDIUM: Unchecked allocation causing crashes
- LOW: Unchecked allocation with limited impact
See Also
patterns.md- Detailed detection patterns and exploitation scenariosexamples.md- Example analysis cases and code samplesreferences.md- CWE references and mitigation strategies
微信扫一扫