Skip to content

Null function pointer dereference in IdoMysqlConnection::OnConfigLoaded() #11075

Description

@Ti-Mis

Hi! I found a potential null dereference issue using the Svace static analyzer.
Problem

IdoMysqlConnection::OnConfigLoaded() obtains the create_mysql_shim function from the MySQL shim library using Library::GetSymbolAddress() and immediately calls the returned function pointer:

auto create_mysql_shim =
shimLibrary.GetSymbolAddress<create_mysql_shim_ptr>("create_mysql_shim");

m_Mysql.reset(create_mysql_shim());

Library::GetSymbolAddress() uses dlsym() on Unix systems and GetProcAddress() on Windows. These functions may return nullptr when the requested symbol is not found.

The returned function pointer is not checked before being called. If create_mysql_shim is missing from the loaded library, the code attempts to call a null function pointer, which results in undefined behavior and may terminate the process.

The library itself is handled separately: failure to load the library causes Library to throw an exception. The issue concerns the case where the library is loaded successfully but the expected symbol is unavailable.

Author T.Mishin

Activity

  1. Ti-Mis commented on Oct 4, 2026

    @Ti-Mis
    Author
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions