8 ms·
So is unmapped address another way of saying null pointer?
by blirio 2y ago
So is unmapped address another way of saying null pointer?
- two_handfuls 2y agoIt’s an invalid pointer yes, but it doesn’t say whether it’s null specifically.
- blirio 2y agoOh wait, I just remembered null is normally 0 in C and C++. So probably not that if it is not 0.
- taspeotis 2y agoWhat? If you have a null pointer to a class, and try to reference the member that starts 156 bytes from the start of the class, you’ll deference 0x9c (0 + 156)
- emmelaich 2y agoStrangely, not necessarily on every implementation on every processor. It's not guaranteed that NULL is 0. Still, I don't think you'd find a counterexample in the wild these days.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- chongli 2y agoNULL isn't always the integer 0 in C. It's implementation-defined.
- loeg 2y agoIn every real world implementation anyone cares about, it's zero. Also I believe it is defined to compare equal to zero in the standard, but don't quote me on that.
- tzs 2y ago> Also I believe it is defined to compare equal to zero in the standard, but don't quote me on that. That's true for the literal constant 0. For 0 in a variable it is not necessarily true. Basically when a literal 0 is assigned to a pointer or compared to a pointer the compiler takes that 0 to mean whatever bit pattern represents the null pointer on the target system.
- cmpxchg8b 2y agoIf you have a page mapped at address 0, accessing address 0 is valid.
- cratermoon 2y agoLooks like a null pointer error to me https://www.youtube.com/watch?v=pCxvyIx922A https://www.youtube.com/watch?v=pCxvyIx922A
- jeffbee 2y ago"Attempt to read from address 0x9c" doesn't strike me as "null pointer". It's an invalid address and it doesn't really matter if it was null or not.
- GeneralMayhem 2y ago0x9c (156 dec) is still a very small number, all things considered. To me that sounds like attempting to access an offset from null - for instance, using a null pointer to a struct type, and trying to access one of its member fields.
- Aloisius 2y agoCould just as easily be accessing an uninitialized pointer, especially given there is a null check immediately before.
- Dwedit 2y ago9C means that it's a NULL address plus some offset of 9C. Like a particular field of a struct.
- loeg 2y agoIt is pretty common for null pointers to structures to have members dereferenced at small offsets, and people usually consider those null dereferences despite not literally being 0. (However, the assembly generated in this case does not match that access pattern, and in fact there was an explicit null check before the dereference.)
- jmb99 2y agoAs an example to illustrate the sibling comments’ explanations: int *array = NULL int position = 0x9C int a = *(array[pos]) //equivalent to *(array + 0x9C) - dereferencing NULL+0x9C, which is just 0x9C This will segfault (or equivalent) due to reading invalid memory at address 0x9C. Most people would call array[pos] a null pointer dereference casually, even though it’s actually a 0x9C pointer dereference, because there’s very little effective difference between them. Now, whether this case was actually something like this (dereferencing some element of a null array pointer) or something like type confusion (value 0x9C was supposed to be loaded into an int, or char, or some other non-pointer type) isn’t clear to me. But I haven’t dug into it really, someone smarter than me could probably figure out which it is.
- saagarjha 2y agoIt seems unlikely that it's a null pointer: https://twitter.com/taviso/status/1814762302337654829 https://twitter.com/taviso/status/1814762302337654829
- leeter 2y agoNo this is kernelspace, an so while all addresses are 'virtual' an unmapped address is an address that hasn't been mapped in the page tables. Normally critical kernel drivers and data are marked as non-pagable (note: The Linux Kernel doesn't page, NTKernel does a legacy of when it was first written and memory constraints of the time). So if a driver needs to access pagable data it must not be part of the storage flow (and Crowdstrike is almost certainly part of it), and at the correct IRQL (the Interrupt priority level, anything above dispatch, AKA the scheduler, has severe restraints on what can happen there). So no an unmapped address is a completely different BSOD, usually PAGE_FAULT_IN_UNPAGED_AREA which is a very bad sign
- jkrejcha 2y agoPAGE_FAULT_IN_NONPAGED_AREA[1]... was the BSOD that occurred in this case. That's basically the first sign that it was a bad pointer dereference in the first place. (DRIVER_)IRQL_NOT_LESS_OR_EQUAL[2][3] is not this case, but it's probably one of the most common reasons drivers crash the system generally. Like you said it's basically attempting to access pageable memory at a time that paging isn't allowed (i.e. when at DISPATCH_LEVEL or higher). [1]: https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/bug-check-0x50--page-fault-in-nonpaged-area https://learn.microsoft.com/en-us/windows-hardware/drivers/d... [2]: https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/bug-check-0xa--irql-not-less-or-equal https://learn.microsoft.com/en-us/windows-hardware/drivers/d... [3]: https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/bug-check-0xd1--driver-irql-not-less-or-equal https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
- loeg 2y agoNo; lots of virtual addresses are not mapped. Null is a subset of all unmapped addresses.