Skip to content

fix oob read in getSpelling when node has no ext tokens - #8907

Merged
danmar merged 2 commits into
cppcheck-opensource:mainfrom
Nussu06:clangimport-getspelling-bounds
Oct 10, 2026
Merged

danmar merged 2 commits into
cppcheck-opensource:mainfrom
Nussu06:clangimport-getspelling-bounds

Conversation

@Nussu06

@Nussu06 Nussu06 commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

getSpelling() sets typeIndex to mExtTokens.size() - 1 and, for node types other than the FunctionDecl and DeclRefExpr branches, reads mExtTokens[typeIndex - 1] without the typeIndex <= 0 check those two branches already apply. A clang AST dump whose node line carries no ext tokens leaves typeIndex at 0 or -1 (size() - 1 wraps into the int), so the read goes out of bounds, which ASAN flags as a SEGV while importing the dump via --clang. Hoist the existing guard ahead of the index so it covers every node type.

Comment thread lib/clangimport.cpp
@dmcppcheck

Copy link
Copy Markdown

Test results for commit 9781751 (tools/test-my-pr.py, main compared to this PR):

Test: http://ec2-16-170-140-253.eu-north-1.compute.amazonaws.com/pr-8907/
packages: 200
Differing warnings: 0 (+0 -0)
Timing: +0.2% (http://ec2-16-170-140-253.eu-north-1.compute.amazonaws.com/pr-8907/2026-10-02_13-25-25-9781751b1038_timing.html)

Posted automatically by the cppcheck PR test runner. +N: warnings only with this PR, -N: warnings only with main. The AI review is written by Claude and can be wrong.

@danmar
danmar merged commit b8e62df into cppcheck-opensource:main Oct 10, 2026
71 checks passed
chrchr-github pushed a commit to chrchr-github/cppcheck that referenced this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants