[previous] 2843 [next] Suspicious: Dereference of an invalid pointer value.
Arrays

Dataflow analysis has identified a code construct which is suspicious. The code may be entirely safe but further investigation is advisable.

An array is being accessed and examination of the immediate context suggests that the element being accessed could sometimes be out of bounds.

For example, in the code shown below, the value of the array subscript 'x' will be '10' (leading to an array bounds violation) unless the parameter 'n' is greater than 0.


/*PRQA S 2017,3120,3132,3203,3227,3408,3605,3689 ++*/
void foo(int n)
{
   int a[10];
   int i;
   int x = 10;

   for (i = 0; i < n; ++i)
   {
      --x;
   }

   a[x] = 1;                      /* 2843 */
}


Certain standard library functions specify that the char array destination argument shall be large enough to store the resulting characters including the null terminator.

This message will also be generated for the following functions where a string literal argument (M) that is too large for the destination array:
function M parameter number
snprintf 3
snprintf_s 3
sprintf 2
strcat 2
strcpy 2
strftime 3
strncat 2
strncpy 2

See also:

QA·C Source Code Analyser 8.1.2
© 2013 Programming Research.
www.programmingresearch.com
Personality Groups | Glossary | Message Index Contents