Skip to content

Commit 8465d90

Browse files
Fix 11396, doublefree on munmap in if-statement (#4594)
1 parent 926bab9 commit 8465d90

2 files changed

Lines changed: 32 additions & 1 deletion

File tree

‎lib/checkleakautovar.cpp‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -477,9 +477,10 @@ bool CheckLeakAutoVar::checkScope(const Token * const startToken,
477477
// check for function call
478478
const Token * const openingPar = isFunctionCall(innerTok);
479479
if (openingPar) {
480+
const Library::AllocFunc* allocFunc = mSettings->library.getDeallocFuncInfo(innerTok);
480481
// innerTok is a function name
481482
const VarInfo::AllocInfo allocation(0, VarInfo::NOALLOC);
482-
functionCall(innerTok, openingPar, varInfo, allocation, nullptr);
483+
functionCall(innerTok, openingPar, varInfo, allocation, allocFunc);
483484
innerTok = openingPar->link();
484485
}
485486
}

‎test/cfg/posix.c‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -892,6 +892,36 @@ void * identicalCondition_mmap(int fd, size_t size) // #9940
892892
return buffer;
893893
}
894894

895+
int munmap_no_double_free(int tofd, // #11396
896+
int fromfd,
897+
size_t len)
898+
{
899+
int rc;
900+
void* fptr = mmap(NULL,len,PROT_READ|PROT_WRITE,MAP_SHARED,fromfd,(off_t)0);
901+
if (fptr == MAP_FAILED) {
902+
return -1;
903+
}
904+
905+
void* tptr = mmap(NULL,len,PROT_READ|PROT_WRITE,MAP_SHARED,tofd,(off_t)0);
906+
if (tptr == MAP_FAILED) {
907+
// cppcheck-suppress memleak
908+
return -1;
909+
}
910+
911+
memcpy(tptr,fptr,len);
912+
913+
if ((rc = munmap(fptr,len)) != 0) {
914+
// cppcheck-suppress memleak
915+
return -1;
916+
}
917+
918+
if ((rc = munmap(tptr,len)) != 0) {
919+
return -1;
920+
}
921+
922+
return rc;
923+
}
924+
895925
void resourceLeak_fdopen(int fd)
896926
{
897927
// cppcheck-suppress unreadVariable

0 commit comments

Comments
 (0)