Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: REM Cost Reform

Using the value of a pointer to a FILE object after the associated file is closed is undefined behavior. (See undefined behavior 148153.) Programs that close the standard streams (especially stdout but also stderr and stdin) must be careful not to use these streams in subsequent function calls, particularly those that implicitly operate on them (such as printf(), perror(), and getc()).

...

Using the value of a pointer to a FILE object after the associated file is closed is undefined behavior 153.

Rule

Severity

Likelihood

Remediation Cost

Detectable

Repairable

Priority

Level

FIO46-C

Medium

Unlikely

No

Medium

No

P4

P2

L3

Automated Detection

Tool

Version

Checker

Description

Astrée
Include Page
Astrée_V
Astrée_V

Supported
CodeSonar
Include Page
CodeSonar_V
CodeSonar_V
IO.UACUse after close
Compass/ROSE
  



Coverity
Include Page
Coverity_V
Coverity_V

USE_AFTER_FREE

Implemented
Helix QAC

Include Page
Helix QAC_V
Helix QAC_V

DF2696, DF2697, DF2698

 


Klocwork
Include Page
Klocwork_V
Klocwork_V

SV.INCORRECT_RESOURCE_HANDLING.URH

 

LDRA tool suite
Include Page
LDRA_V
LDRA_V

48 D

Partially implemented
Parasoft C/C++test
9.5BD-RES-FREE
Include Page
Parasoft_V
Parasoft_V
CERT_C-FIO46-a

Do not use resources that have been freed

PC-lint Plus

Include Page
PC-lint Plus_V
PC-lint Plus_V

2471

Fully supported

 

Polyspace Bug Finder
R2016a

Closing a previously closed resource, Standard function call with incorrect arguments, Use of previously closed resource

Include Page
Polyspace Bug Finder_V
Polyspace Bug Finder_V

CERT C: Rule FIO46-C


Checks for use of previously closed resource (rule partially covered)

Function closes a previously closed stream

Argument to a standard function does not meet requirements for use in the function

Function operates on a previously closed stream

SonarQube C/C++ Plugin
Include Page
SonarQube C/C++ Plugin_V
SonarQube C/C++ Plugin_V
S3588
 

Related Vulnerabilities

Search for vulnerabilities resulting from the violation of this rule on the CERT website.

Bibliography

[IEEE Std 1003.1:2013]XSH, System Interfaces, open
[ISO/IEC 9899:
2011
2024

Subclause 7.

21

23.3, "Files"
Subclause 7.

21

23.5.1, "The fclose Function"

...


...

Image Modified Image Modified Image Modified