Newly introduced findings

List of Findings

Error: GCC_ANALYZER_WARNING (CWE-476): [#def1]
procps-ng-4.0.4/src/pmap.c:1184:17: warning[-Wanalyzer-possible-null-dereference]: dereference of possibly-NULL ‘xmalloc((long unsigned int)argc * 4)’
procps-ng-4.0.4/src/pmap.c:1020:5: enter_function: entry to ‘main’
procps-ng-4.0.4/src/pmap.c:1049:12: branch_false: following ‘false’ branch (when ‘argc > 1’)...
procps-ng-4.0.4/src/pmap.c:1049:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1107:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1110:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1110:13: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1113:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1113:13: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1116:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1116:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1125:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1125:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1140:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1140:12: branch_false: following ‘false’ branch (when ‘argc > 0’)...
procps-ng-4.0.4/src/pmap.c:1143:12: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1143:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1145:13: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1162:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1164:13: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1164:12: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1166:19: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1166:19: call_function: calling ‘xmalloc’ from ‘main’
procps-ng-4.0.4/src/pmap.c:1166:19: return_function: returning to ‘main’ from ‘xmalloc’
procps-ng-4.0.4/src/pmap.c:1169:16: branch_true: following ‘true’ branch...
procps-ng-4.0.4/src/pmap.c:1170:31: branch_true: ...to here
procps-ng-4.0.4/src/pmap.c:1179:20: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1181:23: branch_false: ...to here
procps-ng-4.0.4/src/pmap.c:1182:20: branch_false: following ‘false’ branch...
procps-ng-4.0.4/src/pmap.c:1184:17: danger: ‘xmalloc((long unsigned int)argc * 4) + (long unsigned int)user_count * 4’ could be NULL: unchecked value from [(24)](sarif:/runs/0/results/11/codeFlows/0/threadFlows/0/locations/23)
# 1182|   		if (pid < 1ul || pid > 0x7ffffffful || *endp)
# 1183|   			usage(stderr);
# 1184|-> 		pidlist[user_count++] = pid;
# 1185|   	}
# 1186|   

Scan Properties

analyzer-version-clippy1.92.0
analyzer-version-cppcheck2.19.1
analyzer-version-gcc16.0.0
analyzer-version-gcc-analyzer16.0.0
analyzer-version-shellcheck0.11.0
analyzer-version-unicontrol0.0.2
diffbase-analyzer-version-clippy1.92.0
diffbase-analyzer-version-cppcheck2.19.1
diffbase-analyzer-version-gcc16.0.0
diffbase-analyzer-version-gcc-analyzer16.0.0
diffbase-analyzer-version-shellcheck0.11.0
diffbase-analyzer-version-unicontrol0.0.2
diffbase-enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
diffbase-exit-code0
diffbase-hostip-172-16-1-99.us-west-2.compute.internal
diffbase-known-false-positives/usr/share/csmock/known-false-positives.js
diffbase-known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
diffbase-mock-configfedora-rawhide-x86_64
diffbase-project-nameprocps-ng-4.0.4-7.fc43
diffbase-store-results-to/tmp/tmpyy5p5mls/procps-ng-4.0.4-7.fc43.tar.xz
diffbase-time-created2026-01-08 20:24:07
diffbase-time-finished2026-01-08 20:26:50
diffbase-toolcsmock
diffbase-tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmpyy5p5mls/procps-ng-4.0.4-7.fc43.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmpyy5p5mls/procps-ng-4.0.4-7.fc43.src.rpm'
diffbase-tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9
enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
exit-code0
hostip-172-16-1-99.us-west-2.compute.internal
known-false-positives/usr/share/csmock/known-false-positives.js
known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
mock-configfedora-rawhide-x86_64
project-nameprocps-ng-4.0.4-9.fc44
store-results-to/tmp/tmpjyqrkk_u/procps-ng-4.0.4-9.fc44.tar.xz
time-created2026-01-08 20:27:12
time-finished2026-01-08 20:29:27
titleNewly introduced findings
toolcsmock
tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmpjyqrkk_u/procps-ng-4.0.4-9.fc44.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmpjyqrkk_u/procps-ng-4.0.4-9.fc44.src.rpm'
tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9