Examples of errors detected by the V531 diagnostic.


V531. It is odd that a sizeof() operator is multiplied by sizeof().


XUIFramework

V531 It is odd that a sizeof() operator is multiplied by sizeof(). Borne pphtmldrawer.cpp 258


CPPString CPPHtmlDrawer::GetStringFromDll(....)
{
  ...
  TCHAR szTemp[256];

  DWORD dwLen = ::LoadString(hInstDll, dwID,
    szTemp, (sizeof(szTemp) * sizeof(TCHAR)));
  ...
}

The LoadString function takes the buffer's size in characters as the last argument. In the Unicode version of the application, we will tell the function that the buffer's size is larger than it is actually. This may cause a buffer overflow. Note that if we fix the code in the following way, it will not become correct at all: sizeof(szTemp) / sizeof(TCHAR).

Similar errors can be found in some other places:

  • V531 It is odd that a sizeof() operator is multiplied by sizeof(). Borne pphtmldrawer.cpp 262

NetDefender Firewall

V531 It is odd that a sizeof() operator is multiplied by sizeof(). fire pphtmldrawer.cpp 258


CPPString CPPHtmlDrawer::GetStringFromDll(....)
{
  ...
  TCHAR szTemp[256];
  DWORD dwLen = ::LoadString(hInstDll, dwID, szTemp,
                             (sizeof(szTemp) * sizeof(TCHAR)));
  ...
}

The LoadString function takes the buffer's size in characters as the last argument. In the Unicode version of the application, we will tell the function that the buffer's size is larger than it is actually. This may cause a buffer overflow. Note that if we fix the code in the following way, it will not become correct at all: sizeof(szTemp) / sizeof(TCHAR).


ReactOS

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr eventvwr.c 1112


VOID
DisplayEvent(HWND hDlg)
{
  WCHAR szEventType[MAX_PATH];
  WCHAR szTime[MAX_PATH];
  WCHAR szDate[MAX_PATH];
  ...
  ListView_GetItemText(hwndListView, iIndex, 0, szEventType,
                       sizeof(szEventType) * sizeof(WCHAR));
  ListView_GetItemText(hwndListView, iIndex, 1, szDate,
                       sizeof(szDate) * sizeof(WCHAR));
  ListView_GetItemText(hwndListView, iIndex, 2, szTime,
                       sizeof(szTime) * sizeof(WCHAR));
  ...
}

ReactOS

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1117

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1118

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1119

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1120

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1121

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1122

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1123

V531 It is odd that a sizeof() operator is multiplied by sizeof(). eventvwr.c 1124


VOID
DisplayEvent(HWND hDlg)
{
  WCHAR szEventType[MAX_PATH];
  WCHAR szTime[MAX_PATH];
  WCHAR szDate[MAX_PATH];
  WCHAR szUser[MAX_PATH];
  WCHAR szComputer[MAX_PATH];
  ....
  ListView_GetItemText(...., sizeof(szEventType)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szDate)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szTime)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szSource)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szCategory)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szEventID)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szUser)*sizeof(WCHAR));
  ListView_GetItemText(...., sizeof(szComputer)*sizeof(WCHAR));
  ....
}

CrashRpt library

V531 It is odd that a sizeof() operator is multiplied by sizeof(). httprequestsender.cpp 286


BOOL CHttpRequestSender::InternalSend()
{
  ....
  TCHAR szBuffer[1024]=_T("");
  DWORD dwBuffSize = sizeof(szBuffer)*sizeof(TCHAR);
  ....
}

Oracle VM Virtual Box

V531 It is odd that a sizeof() operator is multiplied by sizeof(). tstrtfileaio.cpp 61


void
tstFileAioTestReadWriteBasic(...., uint32_t cMaxReqsInFlight)
{
  /* Allocate request array. */
  RTFILEAIOREQ *paReqs;
  paReqs = (...., cMaxReqsInFlight * sizeof(RTFILEAIOREQ));
  RTTESTI_CHECK_RETV(paReqs);
  RT_BZERO(..., sizeof(cMaxReqsInFlight) * sizeof(RTFILEAIOREQ));

  /* Allocate array holding pointer to data buffers. */
  void **papvBuf = (...., cMaxReqsInFlight * sizeof(void *));
  ....
}


Do you make errors in the code?

Check your code
with PVS-Studio

Static code analysis
for C, C++, and C#

goto PVS-Studio;
We use cookies for the analysis of events to improve our content and make user interaction more convenient. By continuing the view of our web-pages you accept the terms of using these files. You can find out more about cookie-files and privacy policy or close the notification, by clicking on the button. Learn More →
Do not show