NULL pointer dereference

NULL pointer dereference

Description

Dereferencing a pointer that is or may be NULL can terminate the program.

Potential impact

  • Denial of service, information exposure through error handling, and reduced reliability may result.

Remediation

Check for NULL before using a pointer, and return or handle the error on the NULL path.

Examples

Before

c
char *p = NULL;
p[0] = 'x';

After

c
char *p = get_buffer();
if (p == NULL) { return; }
p[0] = 'x';

Explanation:

  • Before: The code dereferences a NULL pointer as an array.
  • After: The code returns if the pointer is NULL and accesses it otherwise. The omitted get_buffer() implementation must return a valid buffer with at least one writable byte at the time of use. A NULL check alone does not guarantee lifetime or capacity.

References