...
Code Block | ||
---|---|---|
| ||
struct buffer { size_t size; char buffer[50]; }; /* ... */ void func(struct buffer *buf) { /* assuming sizeof(size_t) is 4, sizeof(size_t)+sizeof(char)*50 equals 54 */ struct buffer *buf_cpy = malloc(sizeof(size_t)+(sizeof(char)*50)); if (buf_cpy == NULL) { /* Handle malloc() error */ } /* * with padding, sizeof(struct buffer) may be greater than 54, causing * some data to be written outside the bounds of the memory allocated */ memcpy(buf_cpy, buf, sizeof(struct buffer)); } |
...
Wiki Markup |
---|
\[[Dowd 06|AA. C References#Dowd 06]\] Chapter 6, "C Language Issues" (Structure Padding 284-287) \[[ISO/IEC 9899-1999|AA. C References#ISO/IEC 9899-1999]\] Section 6.7.2.1, "Structure and union specifiers" |
...
EXP02-A. The second operands of the logical AND and OR operators should not contain side effects 03. Expressions (EXP) EXP04-A. Do not perform byte-by-byte comparisons between structures