Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: REM Cost Reform

...

Failure to enclose calls to the cnd_wait() or cnd_timedwait() functions inside a while loop can lead to indefinite blocking and denial of service (DoS).

Rule

Severity

LikelihoodRemediation Cost

Detectable

Repairable

Priority

Level

CON36-C

Low

Unlikely

Yes

MediumNo

P2

L3

Automated Detection

Tool

Version

Checker

Description

CodeSonar
Include Page
CodeSonar_V
CodeSonar_V

LANG.STRUCT.ICOL
CONCURRENCY.BADFUNC.CNDWAIT

Inappropriate Call Outside Loop
Use of Condition Variable Wait

Cppcheck Premium

Include Page
Cppcheck Premium_V
Cppcheck Premium_V

premium-cert-con36-c
Helix QAC

Include Page
Helix QAC_V
Helix QAC_V

C2027
Klocwork
Include Page
Klocwork_V
Klocwork_V

CERT.CONC.WAKE_IN_LOOP_C


Parasoft C/C++test

Include Page
Parasoft_V
Parasoft_V

CERT_C-CON36-a

Wrap functions that can spuriously wake up in a loop

Polyspace Bug Finder

Include Page
Polyspace Bug Finder_V
Polyspace Bug Finder_V

CERT C: Rule CON36-CChecks for situations where functions that can spuriously wake up are not wrapped in loop (rule fully covered)

Related Vulnerabilities

Search for vulnerabilities resulting from the violation of this rule on the CERT website

...

Taxonomy

Taxonomy item

Relationship

CERT Oracle Secure Coding Standard for JavaTHI03-J. Always invoke wait() and await() methods inside a loopPrior to 2018-01-12: CERT: Unspecified Relationship

Bibliography

...

[Lea 2000]

1.3.2, "Liveness"
3.2.2, "Monitor Mechanics"

...