Coverage area · 6 checks
Memory safety and race conditions in C and C++
In C and C++, a single unchecked copy or overflowing size calculation can let input overwrite memory. OpenRouting surfaces those patterns in your repository and reviews whether the input is actually bounded.
Illustrative example of how a finding in this area is reviewed.
Why this area matters
Memory-safety bugs — out-of-bounds writes (CWE-787), out-of-bounds reads (CWE-125), use-after-free (CWE-416) — are consistently at the top of the CWE Top 25, and vendors such as Microsoft and Google have reported that roughly 70% of their serious security bugs fall in this class. Race conditions between checking a resource and using it (TOCTOU, CWE-367) are a close relative.
Static rules for C are blunt: they flag every strcpy and memcpy, including ones whose size is provably fine. The review step reads the surrounding code to see whether the destination is large enough, whether the length was checked, and whether the input comes from outside the program.
What goes wrong in real applications
Buffer overflows
Copying input into a fixed-size buffer without a length check can overwrite adjacent memory. Consequences range from crashes to an attacker controlling execution.
Integer overflow in size calculations
When count × size wraps around, a small allocation is followed by a large write. The overflow happens in arithmetic that looks harmless.
Use-after-free and double free
Using memory after it has been released corrupts allocator state. These bugs are often reachable from input and hard to spot by reading one function.
Format-string bugs
Passing user input as the format argument to printf-style functions lets it read or write memory.
Check-then-use races (TOCTOU)
Checking a file's permissions or path and then opening it separately leaves a window where it can be swapped, so the program acts on something it never checked.
Sample: the risky pattern and the fix
#include <string.h>
void set_display_name(struct user *u, const char *input) {
char buf[32];
strcpy(buf, input); /* no bound on input length */
u->name = strdup(buf);
}#include <string.h>
int set_display_name(struct user *u, const char *input) {
char buf[32];
size_t len = strnlen(input, sizeof(buf));
if (len >= sizeof(buf))
return -1; /* reject over-long input */
memcpy(buf, input, len + 1); /* fits, including the terminator */
u->name = strdup(buf);
return u->name ? 0 : -1;
}strcpy copies until it finds a terminator, so any input longer than 31 bytes writes past the end of the stack buffer. The fix measures the input with a bound, rejects anything that doesn't fit, and only then copies a known length.
Illustrative code, simplified for clarity — not taken from a customer repository.
What OpenRouting checks in your repository
- Unbounded copy and format functions: strcpy, strcat, sprintf, gets, printf with a non-literal format
- Size arithmetic feeding malloc, memcpy and array indexes
- Check-then-use file access, predictable temporary files and symlink-following opens
- Whether the input length is already validated or the source is trusted (the usual false-positive signal)
Scope and limits
- It doesn't compile, run, fuzz or debug your code, and it never builds exploits. Bugs that need execution to find — complex use-after-free across modules, timing-dependent races — are better caught with sanitizers and fuzzing.
- There is no dedicated memory-safety specialist yet: these findings are reviewed by the general reviewer, and temp-file or symlink races by the file-permissions agent.
Coverage areas reflect OpenRouting's check library. Code, secret and infrastructure scanning run today; other areas are rolling out. Scanners surface candidates and a review agent decides whether each one is real — it doesn't promise to find every issue.
Review agents for this area
- Privilege & file permissions — Checks file permissions, temp files, symlinks and unnecessary root.
Common questions
Does OpenRouting replace AddressSanitizer or fuzzing?
No. It reviews source statically. Sanitizers and fuzzers find bugs by running code, which OpenRouting never does. The two complement each other.
Does it support Rust?
Safe Rust rules out most of this class. Findings in unsafe blocks are reviewed like any other, but stock rule coverage for Rust is narrower than for C and C++.