CVE-2024-36613: Div Round Up Intermediate Overflow
The bounds check guards against overflow for the final result of `$X + $Y - 1`, but left-to-right evaluation means `$X + $Y` is computed first. If `$X` exactly equals `$MAX - $Y + 1`, `$X + $Y` evaluates to `$MAX + 1`, which can cause a signed integer overflow before subtraction. Rewrite as `$X - 1 + $Y` to ensure all intermediate calculations safely prevent
greprules fetch cve-2024-36613-div-round-up-intermediate-overflow --engine opengrepDescription
The bounds check guards against overflow for the final result of `$X + $Y - 1`, but left-to-right evaluation means `$X + $Y` is computed first. If `$X` exactly equals `$MAX - $Y + 1`, `$X + $Y` evaluates to `$MAX + 1`, which can cause a signed integer overflow before subtraction. Rewrite as `$X - 1 + $Y` to ensure all intermediate calculations safely prevent
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0