Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/zfs-fuse-0.7.0/src/cmd/zstreamdump/zstreamdump.c Examining data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_util.c Examining data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_iter.c Examining data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c Examining data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_util.h Examining data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c Examining data/zfs-fuse-0.7.0/src/cmd/stat/common/timestamp.c Examining data/zfs-fuse-0.7.0/src/cmd/stat/common/statcommon.h Examining data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c Examining data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_iter.c Examining data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_iter.h Examining data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c Examining data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_util.h Examining data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c Examining data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/cmd_listener.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/util.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_rlock.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfsfuse_socket.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_dir.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/fuse_listener.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/fuse_listener.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfsfuse_socket.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/util.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/fuse.h Examining data/zfs-fuse-0.7.0/src/zfs-fuse/cmd_listener.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_replay.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/main.c Examining data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c Examining data/zfs-fuse-0.7.0/src/lib/libavl/include/sys/avl_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libavl/include/sys/avl.h Examining data/zfs-fuse-0.7.0/src/lib/libavl/avl.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/mutex.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/lint.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/thread.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/zmod.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vfs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/taskq.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kcf_random.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/flock.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/rwlock.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/libsolkerncompat.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/acl/acl_common.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/fcntl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/tsol/label.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dditypes.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/thread.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/refstr.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/sysevent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/attr.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/aio_req.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/semaphore.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/mount.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/cmn_err.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/conf.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/flock.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/fcntl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/param.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/systm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/sid.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vmsystm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vfs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/sunldi.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/zfs_context.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/efi_partition.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dirent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/crc32.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/rwstlock.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/debug.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/cred.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/t_lock.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vfs_opreg.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/ddi.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/taskq.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/condvar.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/unistd.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/priv.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/rwlock.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/mntent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/bootconf.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/cred_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/stropts.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/zfs_debug.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/systeminfo.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/filio.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/kidmap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/fs/swapnode.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/mode.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/stack.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/cpuvar.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/disp.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/extdirent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/machlock.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/callb.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/time.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/mkdev.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/random.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/trap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/buf.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/varargs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/share.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/ctype.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/bitmap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/zone.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dnlc.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/file.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/open.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/fm/protocol.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/fm/util.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vnode.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/bootstat.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/policy.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dumphdr.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/kmem.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/mutex.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/taskq_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/pathname.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/uio.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/refstr_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/sdt.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/kobj.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/fem.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/util/qsort.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/unistd.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/fs/fs_subr.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/strings.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/page.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/seg_kpm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/seg_kmem.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/as.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/pvn.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/anon.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/seg_vn.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/seg_enum.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/vm/kpm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/tsoc/label.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sharefs/share.h Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/clock.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/sid.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/condvar.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/fs_subr.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/policy.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kmem.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/refstr.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/callb.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kobj.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kobj_subr.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/move.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/pathname.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vfs.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c Examining data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/main.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_avl.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_open.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_dprintf.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_misc.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/include/libuutil_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libuutil/include/libuutil_common.h Examining data/zfs-fuse-0.7.0/src/lib/libuutil/include/libuutil.h Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_list.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_strtoint.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_ident.c Examining data/zfs-fuse-0.7.0/src/lib/libuutil/uu_pname.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_status.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfs/include/acl_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfs/include/zfsfuse.h Examining data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs.h Examining data/zfs-fuse-0.7.0/src/lib/libzfs/include/acl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/zfs_fletcher.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_config.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_graph.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c Examining data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_deleg.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/format.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/zfs_deleg.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ctldir.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/metaslab_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_tx.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zio_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/spa_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/refcount.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dir.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/metaslab.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_zfetch.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_vfsops.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_pool.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_prop.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_dir.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/spa_boot.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_znode.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_traverse.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/list.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/compress.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zio.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/ddt.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_file.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_debug.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/txg_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/fs/zfs.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/uberblock_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/txg.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dataset.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_disk.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dbuf.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dnode.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/uberblock.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zio_checksum.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/rprwlock.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zil_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/bplist.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_objset.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/spa.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zvol.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/arc.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zil.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_synctask.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_rlock.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/unique.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/fm/fs/zfs.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/space_map.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/list_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_fuid.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap_leaf.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/rrwlock.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_acl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zio_compress.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_deleg.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/zfs_comutil.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/zfs_prop.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/zfs_fletcher.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/zfs_namecheck.h Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/list.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_prop.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/compress.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_comutil.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_namecheck.c Examining data/zfs-fuse-0.7.0/src/lib/libzfscommon/zpool_prop.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/rprwlock.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_traverse.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_mirror.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_missing.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_cache.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/metaslab.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/ddt_zap.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_synctask.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/taskq.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/kmem_asprintf.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_queue.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zle.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/unique.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/uberblock.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_file.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/include/sys/zfs_context.h Examining data/zfs-fuse-0.7.0/src/lib/libzpool/txg.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fuid.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/spa_history.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_zfetch.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/space_map.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dnode_sync.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/fletcher.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zio_compress.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_tx.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/rrwlock.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_send.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/lzjb.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_object.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_root.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zio_checksum.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zap_leaf.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_scrub.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/kmem_asprintf.h Examining data/zfs-fuse-0.7.0/src/lib/libzpool/gzip.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/spa_errlog.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_pool.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_byteswap.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/refcount.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fm.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_label.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/util.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/bplist.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zio_inject.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dnode.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/sha256.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/spa_config.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/flushwc.h Examining data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c Examining data/zfs-fuse-0.7.0/src/lib/libzpool/flushwc.c Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/include1/sys/kmem.h Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/include/sys/nvpair.h Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/include/sys/nvpair_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/include/libnvpair.h Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair_alloc_system.c Examining data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair_alloc_fixed.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem_mmap.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_test3.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem_base.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/sys/vmem.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/sys/vmem_impl_user.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/getpcstack.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_base.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_test2.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_agent_support.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_update_thread.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/misc.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_fork.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/init_lib.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem_base.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/misc.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem_sbrk.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_fail.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/umem_test.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/vmem_stand.h Examining data/zfs-fuse-0.7.0/src/lib/libumem/malloc.c Examining data/zfs-fuse-0.7.0/src/lib/libumem/sol_compat.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/lint.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/mkdirp.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/generic/atomic.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/u8_textprep.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/gen_synonyms.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/thread.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/string.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/stdio_ext.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/rpc/xdr.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sparc64/sys/asm_linkage.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/libdiskmgt.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/i386/sys/asm_linkage.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/tsol/label.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mnttab.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/note.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/byteorder.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sysevent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/zmod.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mount.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/cmn_err.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/acl_impl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/param.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/systm.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/processor.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sysevent/eventdefs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/efi_partition.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/debug.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/cred.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/ddi.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/inttypes.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mntio.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sysmacros.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/priv.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mntent.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/user.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/stropts.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/systeminfo.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/rctl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vmem.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/stack.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/ioctl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/int_types.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/types.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/uuid.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/idmap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/va_list.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/callb.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/time.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mkdev.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/trap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/feature_tests.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/int_limits.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/u8_textprep_data.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/varargs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/bitmap.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/u8_textprep.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/zone.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/file.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/stat.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/fm/protocol.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/fm/util.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sunddi.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/types32.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/acl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/modctl.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kmem.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/proc.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/uio.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sdt.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/isa_defs.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/utsname.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/ucred.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/amd64/sys/asm_linkage.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/unistd.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/priv.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/ia32/sys/asm_linkage.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/devid.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/libgen.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/strings.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/libdevinfo.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/libshare.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/unistd_aux.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/synch.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/libc.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/mtlib.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/stdarg.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/zone.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/atomic.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/aclutils.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/tsd.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/strlcpy.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/strlcat.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/atomic_asm_weak.h Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/zone.c Examining data/zfs-fuse-0.7.0/src/lib/libsolcompat/getmntany.c FINAL RESULTS: data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:870:22: [5] (race) readlink: This accepts filename arguments; if an attacker can move those files or change the link content, a race condition results. Also, it does not terminate with ASCII NUL. (CWE-362, CWE-20). Reconsider approach. VOPSTATS_UPDATE(vp, readlink); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3615:10: [5] (buffer) strncat: Easily used incorrectly (e.g., incorrectly computing the correct maximum size to add) [MS-banned] (CWE-120). Consider strcat_s, strlcat, snprintf, or automatically resizing strings. Risk is high; the length parameter appears to be a constant, instead of computing the number of characters left. (void) strncat(buf, zc->zc_value, MAXPATHLEN); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:172:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, fmt, ap); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1486:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(header ? header : ""); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1498:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(footer ? footer : ""); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_iter.c:161:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(col->sc_user_prop, name); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1641:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(cb->cb_lastfs, zfs_get_name(zhp)); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1829:9: [4] (shell) execv: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. (void) execv(pypath, argv-1); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3253:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(&mntopts[len], newopts); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3869:9: [4] (shell) execv: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. (void) execv(pypath, argv-1); data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4336:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy((void *)buf, argv[2]); data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:112:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, fmt, ap); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:389:9: [4] (format) vsprintf: Potential format string problem (CWE-134). Make format string constant. (void) vsprintf(buf + strlen(buf), message, args); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:655:11: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(path, ztest_aux_template, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:659:11: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(path, ztest_dev_template, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2240:11: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(path, ztest_aux_template, zopt_dir, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2451:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(oldpath, oldvd->vdev_path); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2475:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(newpath, newvd->vdev_path); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2477:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(newpath, sizeof (newpath), ztest_dev_template, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3011:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap1name, MAXNAMELEN, "%s@s1_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3012:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(clone1name, MAXNAMELEN, "%s/c1_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3013:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap2name, MAXNAMELEN, "%s@s2_" FU64, clone1name, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3014:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(clone2name, MAXNAMELEN, "%s/c2_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3015:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap3name, MAXNAMELEN, "%s@s3_" FU64, clone1name, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3055:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap1name, MAXNAMELEN, "%s@s1_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3056:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(clone1name, MAXNAMELEN, "%s/c1_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3057:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap2name, MAXNAMELEN, "%s@s2_" FU64, clone1name, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3058:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(clone2name, MAXNAMELEN, "%s/c2_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3059:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snap3name, MAXNAMELEN, "%s@s3_" FU64, clone1name, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3768:9: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(propname, "prop_" FU64, prop); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3769:9: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(txgname, "txg_" FU64, prop); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3830:9: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(propname, "prop_" FU64, prop); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3831:9: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(txgname, "txg_" FU64, prop); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3878:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(name, sizeof (name), "fzap-" FU64 "-" FU64, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4274:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(snapname, 100, "sh1_" FU64, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4276:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(clonename, 100, "%s/ch1_" FU64, osname, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4277:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(tag, 100, "tag_" FU64, id); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4418:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(path0, sizeof (path0), ztest_dev_template, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4420:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(pathrand, sizeof (pathrand), ztest_dev_template, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4462:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(path0, vd0->vdev_path); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4463:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(pathrand, vd0->vdev_path); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4668:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(newname, oldname); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4718:10: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. (void) sprintf(zdb, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4728:7: [4] (shell) popen: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. fp = popen(zdb, "r"); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:417:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, "bad config type " data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:533:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi8, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:544:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi8, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:556:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi8, (int8_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:567:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi8, (int8_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:579:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi16, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:590:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi16, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:602:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi16, (int16_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:613:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi16, (int16_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:625:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:636:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:648:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, (int32_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:659:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, (int32_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:671:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi64, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:682:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi64, &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:694:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi64, (int64_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:705:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi64, (int64_t *)&val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:717:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, (int *) &val_arg); data/zfs-fuse-0.7.0/src/lib/libnvpair/libnvpair.c:728:8: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. sr = sscanf(value, "%"SCNi32, (int *) &val_arg); data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mount.h:66:2: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(newspec, FUSESPEC); data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mount.h:67:2: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). strcat(newspec, spec); data/zfs-fuse-0.7.0/src/lib/libsolcompat/mkdirp.c:89:7: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. if (access(str, F_OK) == 0) data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:561:3: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_READ_ACL | ACE_READ_ATTRIBUTES; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:563:4: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_WRITE_ACL; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:566:4: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_WRITE_ACL; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:571:3: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_READ_DATA; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:575:3: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_WRITE_DATA | data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:578:4: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_DELETE_CHILD; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:582:3: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. access |= ACE_EXECUTE; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:585:10: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. return (access); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:46:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(real_fmt, ce_prefix[CE_PANIC]); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:47:9: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(real_fmt, fmt); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:78:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(real_fmt, ce_prefix[ce]); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:79:9: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(real_fmt, fmt); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/systm.h:74:2: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(to, from); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:215:2: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. sprintf(kstat_str,FI64 "\n",file->value.i64); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:218:2: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. sprintf(kstat_str,FU64 "\n",file->value.ui64); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/refstr.c:47:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(rsp->rs_string, str); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:578:9: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. (void) sprintf(realpath, "/%s", path); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:1196:22: [4] (race) access: This usually indicates a security flaw. If an attacker can change anything along the path between the call to access() and the file's actual use (e.g., by moving files), the attacker can exploit the race condition (CWE-362/CWE-367!). Set up the correct permissions (e.g., using setuid()) and try to open the file directly. VOPSTATS_UPDATE(vp, access); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:199:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(buf, UMEM_MAX_ERROR_SIZE-1, format, va); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:219:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(buf, UMEM_MAX_ERROR_SIZE-1, format, va); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:231:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(buf, UMEM_MAX_ERROR_SIZE-1, format, va); data/zfs-fuse-0.7.0/src/lib/libumem/umem_test2.c:39:7: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(testcases[i][j], TESTSTRINGS[i]); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c:79:6: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. M = vsnprintf(attic, 1, format, args); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c:88:7: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. M = vsnprintf(b, m + 1, format, args); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_dprintf.c:107:9: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, FACILITY_FMT, D->uud_name, data/zfs-fuse-0.7.0/src/lib/libuutil/uu_dprintf.c:111:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, format, alist); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_misc.c:202:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, format, args); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_pname.c:92:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, PNAME_FMT, pname); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_pname.c:94:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, format, alist); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_pname.c:97:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, ERRNO_FMT, strerror(err)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:304:10: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(newname, cn->cn_handle->zfs_name + strlen(src)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_config.c:235:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zhp->zpool_name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:523:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1373:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1460:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2607:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2815:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3042:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3076:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3161:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3214:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3261:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3510:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3580:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3636:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3989:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:4137:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_graph.c:597:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(result[*idx], zgv->zv_dataset); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:335:11: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(buf, sizeof (buf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:383:25: [4] (shell) execlp: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. if (flags & MS_FORCE) execlp("umount","umount","-l",mountpoint,NULL); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:384:8: [4] (shell) execlp: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. else execlp("umount","umount",mountpoint,NULL); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:601:3: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(opts,s+1); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:608:3: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. sprintf(buff,"exportfs -o %s '%s:%s'",opts,hostname,mountpoint); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:609:7: [4] (shell) system: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. if (system(buff) != 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:623:2: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. sprintf(buff,"exportfs -o fsid=%d,no_subtree_check '*:%s'",fsid,mountpoint); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:624:12: [4] (shell) system: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. int ret = system(buff); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:638:5: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(share,mshare); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:679:6: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(s+1,s+4); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:682:2: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. sprintf(buff,"exportfs -u '%s:%s'",hostname,(char*)share); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:684:12: [4] (shell) system: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. int ret = system(buff); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:619:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:930:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1066:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1104:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1224:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1306:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1311:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1316:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1320:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1323:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1326:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1346:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, "action: ")); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1348:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, "\t")); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1359:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1364:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1369:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1375:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1379:10: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1385:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1389:11: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1394:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1398:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1404:9: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) printf(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1468:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1530:11: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(desc, sizeof (desc), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1534:11: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(desc, sizeof (desc), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1610:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1904:8: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. rsz = snprintf(physpath + pos, bytes_left, format, tmppath); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2079:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2082:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2150:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2198:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2233:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2297:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2300:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2388:11: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, "Please " data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2396:11: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, "Make " data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2482:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2584:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2791:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2838:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2842:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2901:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(msg, sizeof (msg), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3082:3: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(str,path); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3133:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zhp->zpool_name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3217:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zhp->zpool_name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3533:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3681:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:869:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:927:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(sdd->prevsnap, thissnap); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:971:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(sdd->prevsnap, thissnap); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1157:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1435:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(newname, tryname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1550:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(gtnd->name, zhp->zfs_name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1940:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2125:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2128:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2139:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2227:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2294:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(&cp[1], drrb->drr_toname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2340:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_top_ds, tosnap); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2341:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_value, tosnap); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2373:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2376:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zc.zc_value); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2383:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(suffix, strrchr(zc.zc_value, '/')); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2387:12: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(zc.zc_value, suffix); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2395:10: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2398:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zc.zc_value); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2403:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(snap, strchr(zc.zc_value, '@')); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2407:12: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(zc.zc_value, snap); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2412:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc.zc_name, zc.zc_value); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2553:12: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(tbuf, sizeof (tbuf), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2570:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc2.zc_name, zc.zc_value); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2690:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, "Warning: " data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2696:10: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, "Warning: " data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2735:9: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) snprintf(errbuf, sizeof (errbuf), dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:236:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(hdl->libzfs_desc, sizeof (hdl->libzfs_desc), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:246:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(hdl->libzfs_action, sizeof (hdl->libzfs_action), data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:257:11: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) fprintf(stderr, dgettext(TEXT_DOMAIN, "internal " data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:223:9: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. (void) sprintf(name, DMU_POOL_DDT, data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:800:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(sn->failed, name); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:850:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(sn.failed, fsname); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:882:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(fsname, sn.failed); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:1283:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(name, attr.za_name); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:1322:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(name, attr.za_name); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:666:12: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(name, ds->ds_snapname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:669:12: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(name, ds->ds_snapname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:894:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(da->failed, name); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2185:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(ds->ds_snapname, newsnapname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:127:12: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(dd->dd_myname, tail); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:136:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(dd->dd_myname, spa_name(dp->dp_spa)); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:202:10: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(buf, dd->dd_myname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:205:10: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). (void) strcat(buf, dd->dd_myname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:255:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(component, path); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:1328:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(dd->dd_myname, ra->mynewname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:137:14: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(setpoint, data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:213:13: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(setpoint, data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:256:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy((char *)cbr->cbr_propname, propname); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:445:9: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. (void) sprintf(realpath, "/%s", path); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:618:10: [4] (format) vprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vprintf(fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:638:9: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:661:10: [4] (format) vfprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. (void) vfprintf(stderr, fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:932:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. size = vsnprintf(NULL, 0, fmt, adx) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:938:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. size = vsnprintf(buf, size, fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/kmem_asprintf.c:13:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. size = vsnprintf(NULL, 0, fmt, adx) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/kmem_asprintf.c:19:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. size = vsnprintf(buf, size, fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:3597:10: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. (void) sprintf(oldvd->vdev_path, "%s/%s", data/zfs-fuse-0.7.0/src/lib/libzpool/spa_history.c:412:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(str, HIS_MAX_RECORD_LEN, fmt, adx); data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c:1161:17: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. SPRINTF_BLKPTR(snprintf, ' ', buf, bp, type, checksum, compress); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:130:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(tname, cname); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:3062:13: [4] (shell) system: This causes a new program to execute and is difficult to use safely (CWE-78). try using a library call that implements the same functionality if available. int ret = system(cmd); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:3071:6: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(old_name,top->spa_name); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_file.c:84:6: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. sprintf(path,"/dev/disk/by-uuid/" FX64_UP,vd->vdev_guid); data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c:947:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(name, za->za_name); data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:930:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(mze->mze_name, zn->zn_key_orig); data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:1266:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(za->za_name, mze->mze_phys.mze_name); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:408:5: [4] (format) snprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. snprintf(argv[1], original_len + 2, strlen(original)>1? "--%s" : "-%s", original); data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c:77:2: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. fprintf((FILE *) arg, END_TRACE "\n"); data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c:110:2: [4] (format) sprintf: Potential format string problem (CWE-134). Make format string constant. sprintf(fname, PTRACE_OUTPUT, getpid(), atomic_inc_32_nv(&thread_n)); data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c:124:2: [4] (format) fprintf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. fprintf(ret, START_TRACE "\n"); data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:297:7: [4] (buffer) sscanf: The scanf() family's %s operation, without a limit specification, permits buffer overflows (CWE-120, CWE-20). Specify a limit to %s, or use a different input function. If the scanf format is influenceable by an attacker, it's exploitable. if (sscanf(tok, spec, &pos) >= 0 && (-1!=pos)) data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:342:3: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). strcat(real_opts,fuse_mount_options); // comes with a starting , data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:344:3: [4] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. sprintf(&real_opts[strlen(real_opts)],",%s",opt); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:133:9: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. (void) vsnprintf(buf, sizeof (buf), fmt, adx); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:1998:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc->zc_name, dsname); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3249:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc->zc_name, dataset); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3254:10: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zc->zc_value, nvpair_name(pair)); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3392:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(tofs, zc->zc_value); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:54:21: [4] (format) printf: If format strings can be influenced by an attacker, they can be exploited (CWE-134). Use a constant for the format specification. #define print_debug printf data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:307:3: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(&outbuf[used],s); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:1248:9: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(outpath, bpath); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2070:11: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). (void) strcpy(zap.za_name, ZFS_CTLDIR_NAME); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2773:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "bcdhilmsuCDRSAFLXevp:t:U:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:418:6: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. if (getenv("ZFS_ABORT") != NULL) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:499:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "o:p")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:617:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":V:b:so:p")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:946:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "dfrR")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1230:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":d:o:s:rHp")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1457:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "rS")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1670:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "rvV:a")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2017:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":d:o:rt:Hs:S:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2146:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "pr")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2350:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "rRf")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2524:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "ro:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2582:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":i:I:RDpv")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2704:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":denuvF")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2775:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, opts)) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3266:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, op == OP_MOUNT ? ":avo:O" : "a")) data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3579:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, op == OP_SHARE ? "a" : "af")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3890:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":mo:O")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3978:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "f")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:4121:6: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. if (getenv("ZFS_ABORT") != NULL) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:327:6: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. if (getenv("ZFS_ABORT") != NULL) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:444:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "fno:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:617:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":fnR:m:o:O:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:848:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "f")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:919:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "fF")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:1660:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":aCc:d:DEfFno:rR:VX")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2210:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "T:v")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2515:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":Ho:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2596:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "fo:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2737:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "f")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2808:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":R:no:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2929:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "et")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3006:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "ft")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3066:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "FnX")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3172:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "s")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3683:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "vxD")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3843:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":avV:")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4100:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, "li")) != -1) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4350:6: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. if (getenv("ZFS_ABORT") != NULL) { data/zfs-fuse-0.7.0/src/cmd/zstreamdump/zstreamdump.c:99:14: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((c = getopt(argc, argv, ":vC")) != -1) { data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:516:16: [3] (buffer) getopt: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((opt = getopt(argc, argv, data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:578:17: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. (void) sprintf(realpath, "/%s", path); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:581:16: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. ret = vn_open(realpath, x1, flags, mode, vpp, x2, x3); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:583:12: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. kmem_free(realpath, strlen(path) + 2); data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:113:9: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. #define getenv(x) safe_getenv(x) data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:639:32: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. cur_env->env_getenv_result = getenv(cur_env->env_name); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_pname.c:124:8: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. cp = getenv("UU_DIE_ABORTS"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:972:7: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. if (realpath(dir[i], path) == 0) { data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:445:17: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. (void) sprintf(realpath, "/%s", path); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:448:16: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. ret = vn_open(realpath, x1, flags, mode, vpp, x2, x3); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:450:12: [3] (buffer) realpath: This function does not protect against buffer overflows, and some implementations can overflow internally (CWE-120/CWE-785!). Ensure that the destination buffer is at least of size MAXPATHLEN, andto protect against implementation problems, the input argument should also be checked to ensure it is no larger than MAXPATHLEN. umem_free(realpath, strlen(path) + 2); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:570:20: [3] (buffer) getenv: Environment variables are untrustable input if they can be set by an attacker. They can have any content and length, and the same variable can be set more than once (CWE-807, CWE-20). Check environment variables carefully before using them. dprintf_string = getenv("ZFS_DEBUG"); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:243:19: [3] (buffer) getopt_long: Some older implementations do not protect against internal buffer overflows (CWE-120, CWE-20). Check implementation on installation, or limit the size of all string inputs. while ((retval = getopt_long(argc, argv, "-hp:a:e:m:nxo:u:v:s:", longopts, NULL)) != -1) { data/zfs-fuse-0.7.0/src/cmd/stat/common/statcommon.h:120:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char is_name[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/cmd/stat/common/statcommon.h:154:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tid[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/cmd/stat/common/statcommon.h:166:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char is_name[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/cmd/stat/common/statcommon.h:192:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char is_module[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/cmd/stat/common/timestamp.c:51:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dstr[64]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:462:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char maxbuf[5]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:481:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char freebuf[5]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:569:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *types[4] = { "ditto", "single", "double", "triple" }; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:570:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:609:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[DDT_NAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:708:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *name[DTL_TYPES] = { "missing", "partial", "scrub", "outage" }; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:709:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char prefix[256]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:745:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[SPA_MAXBLOCKSIZE]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:751:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tbuf[30]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:752:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char internalstr[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:840:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(blkbuf + strlen(blkbuf), "%llu:%llx:%llx ", data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:845:9: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(blkbuf + strlen(blkbuf), data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:858:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:952:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nice[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1003:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char used[6], compressed[6], uncompressed[6], unique[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1004:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1059:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char bytes[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1060:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char comp[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1061:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char uncomp[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1095:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1172:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN * 2]; /* allow for xattr and failure prefix */ data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1276:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char iblk[6], dblk[6], lsize[6], asize[6], bonus_size[6], fill[7]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1277:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char aux[50]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1305:9: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(fill, "%6.2f", 100.0 * doi.doi_fill_count * data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1364:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char segsize[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1386:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char *objset_types[DMU_OST_NUMTYPES] = { data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1395:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char numbuf[8]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1396:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN + 20]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1397:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char osname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1422:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(blkbuf, ", rootbp "); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1494:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1578:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char header[ZDB_MAX_UB_HEADER_SIZE]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1786:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2011:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2098:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char csize[6], lsize[6], psize[6], asize[6], avg[6]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2332:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2612:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(pbuf, pbuf2, psize); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2808:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(searchdirs, tmp, nsearch * data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:43:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char prefix[4] = "\t\t\t"; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:48:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:122:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[SPA_MAXBLOCKSIZE]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:307:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blkbuf[BP_SPRINTF_LEN + 10]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:315:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(blkbuf, ", "); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_iter.c:264:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char lbuf[ZFS_MAXPROPLEN], rbuf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:60:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char history_str[HIS_MAX_RECORD_LEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:904:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char thissnap[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1110:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1111:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char rbuf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1113:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char source[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1541:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char cb_lastfs[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1626:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char verstr[16]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1780:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char namebuf[32]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1781:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sizebuf[32]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1877:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char headerbuf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1920:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char property[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2346:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parentname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2657:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char origin[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2809:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2932:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(cbp->cb_handles, handles, data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2977:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mounta[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2978:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountb[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3014:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountpoint[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3015:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char shareopts[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3016:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char smbshareopts[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3519:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nfs_mnt_prop[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3520:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char smbshare_prop[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3540:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mtpt_prop[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3575:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nfs_mnt_prop[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3576:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sharesmb[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3882:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountpoint[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3883:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mntopts[MNT_LINE_MAX] = { '\0' }; data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:4050:21: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((mnttab_file = fopen(MNTTAB, "r")) == NULL) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:180:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char history_str[HIS_MAX_RECORD_LEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:731:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:1069:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char rbuf[6], wbuf[6], cbuf[6], repaired[7]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:1674:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(searchdirs, tmp, nsearch * data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:1996:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2428:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char property[ZPOOL_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:3996:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tbuf[30]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4002:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char internalstr[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4132:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char value[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4333:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[16384]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:306:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(file, O_RDONLY)) < 0) data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:374:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:378:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDWR | O_NDELAY)) < 0) data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:402:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:500:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) < 0) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:542:18: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) >= 0) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:729:15: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) >= 0) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:965:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(buf, O_RDONLY)) < 0) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:1035:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) < 0) data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_vdev.c:1079:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:197:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char od_name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:208:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zd_name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:382:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[FATAL_MSG_SZ]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:387:9: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "ztest: "); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:461:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nice_vdev_size[10]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:462:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nice_gang_bang[10]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:643:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char pathbuf[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:665:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). int fd = open(path, O_RDWR | O_CREAT | O_TRUNC, 0666); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:819:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char setpoint[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1110:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&lr->lr_common + 1, &itx->itx_lr + 1, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1127:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&lr->lr_common + 1, &itx->itx_lr + 1, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1160:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&lr->lr_common + 1, &itx->itx_lr + 1, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1175:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&lr->lr_common + 1, &itx->itx_lr + 1, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1190:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&lr->lr_common + 1, &itx->itx_lr + 1, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1443:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, abuf->b_data, length); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1703:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, lr + lrsize, namesize); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1854:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, lr + 1, size); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2238:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2396:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char oldpath[MAXPATHLEN], newpath[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2574:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(vd->vdev_path, O_RDWR)) == -1) data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2792:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char oldnumbuf[6], newnumbuf[6]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2849:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snapname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2869:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snapname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2890:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3004:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap1name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3005:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clone1name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3006:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap2name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3007:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clone2name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3008:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap3name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3043:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap1name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3044:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clone1name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3045:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap2name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3046:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clone2name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3047:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap3name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3587:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((caddr_t)bigbuf + (off - bigoff), data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3590:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((caddr_t)bigbuf + (off - bigoff), data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3593:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((caddr_t)bigbuf + (off - bigoff) + data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3724:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char propname[100], txgname[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3726:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *hc[2] = { "s.acl.h", ".s.open.h.hyLZlg" }; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3873:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3903:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[20], string_value[20]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:3952:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, string_value, namelen); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4264:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snapname[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4265:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char fullname[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4266:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clonename[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4267:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tag[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4268:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char osname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4381:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path0[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4382:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char pathrand[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4507:7: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). fd = open(pathrand, O_RDWR); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4669:9: [2] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). Risk is low because the source is a constant string. (void) strcat(newname, "_tmp"); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4714:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zdb[MAXPATHLEN + MAXNAMELEN + 20]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4715:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zbuf[1024]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4949:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4996:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5204:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5305:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(timebuf, data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5308:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(timebuf, "%lluh%02llum%02llus", h, m, s); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5310:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(timebuf, "%llum%02llus", m, s); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5312:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(timebuf, "%llus", s); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5381:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char timebuf[100]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5382:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char numbuf[6]; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5389:20: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). ztest_random_fd = open("/dev/urandom", O_RDONLY); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:5546:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tmpname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:913:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, NVP_NAME(nvp), name_sz); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:927:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(strs[i], buf, slen); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:965:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, NVP_VALUE(nvp), value_sz); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:1276:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(NVP_VALUE(nvp), data, data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:2495:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(buf, native->n_curr, size); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:2498:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(native->n_curr, buf, size); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:2754:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(native->n_curr, &decode_len, sizeof (int32_t)); data/zfs-fuse-0.7.0/src/lib/libsolcompat/getmntany.c:43:10: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. __thread char buf[BUFSIZE]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:52:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dki_cname[DK_DEVLEN]; /* controller name (no unit #) */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:60:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dki_dname[DK_DEVLEN]; /* drive name (no unit #) */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:376:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vdr_side_name[VOL_SIDENAME]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:397:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vdr_side_name[VOL_SIDENAME]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:434:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_amodel[DKD_ATA_MODEL]; /* 40 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:435:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_afwver[DKD_ATA_FWVER]; /* 8 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:436:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_aserial[DKD_ATA_SERIAL]; /* 20 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:439:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_svendor[DKD_SCSI_VENDOR]; /* 8 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:440:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_sproduct[DKD_SCSI_PRODUCT]; /* 16 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:441:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_sfwver[DKD_SCSI_REVLEVEL]; /* 4 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dkio.h:442:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkd_sserial[DKD_SCSI_SERIAL]; /* 12 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:125:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_volume[LEN_DKL_VVOL]; /* volume name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:131:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_asciilabel[LEN_DKL_ASCII]; /* for compatibility */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:134:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_volume[LEN_DKL_VVOL]; /* volume name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:184:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkl_pad[LEN_DKL_PAD]; /* unused part of 512 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:186:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkl_asciilabel[LEN_DKL_ASCII]; /* for compatibility */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/dklabel.h:190:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dkl_pad[LEN_DKL_PAD]; /* unused part of 512 bytes */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:75:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_module[KSTAT_STRLEN]; /* provider module name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:78:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_name[KSTAT_STRLEN]; /* kstat name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:80:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_class[KSTAT_STRLEN]; /* kstat class */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:106:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_module[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:109:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_name[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:111:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ks_class[KSTAT_STRLEN]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:444:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[KSTAT_STRLEN]; /* name of counter */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:447:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char c[16]; /* enough for 128-bit ints */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:456:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char __pad[8]; /* 64-bit padding */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/kstat.h:689:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[KSTAT_STRLEN]; /* event name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sysmacros.h:69:17: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. extern unsigned char byte_to_bcd[256]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/sysmacros.h:70:17: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. extern unsigned char bcd_to_byte[256]; data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:109:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_volume[LEN_DKL_VVOL]; /* volume name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:115:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_asciilabel[LEN_DKL_ASCII]; /* for compatibility */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:130:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_volume[LEN_DKL_VVOL]; /* volume name */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:136:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char v_asciilabel[LEN_DKL_ASCII]; /* for compatibility */ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:147:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(v32.v_volume, v.v_volume, LEN_DKL_VVOL); \ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:161:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(v32.v_asciilabel, v.v_asciilabel, LEN_DKL_ASCII); \ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:172:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(v.v_volume, v32.v_volume, LEN_DKL_VVOL); \ data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/vtoc.h:190:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(v.v_asciilabel, v32.v_asciilabel, LEN_DKL_ASCII); \ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:390:9: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(tmp, ptr, (size < new_size) ? size : new_size); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:595:9: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(deny, allow, sizeof (ace_t)); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:884:11: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(acep + acecnt, dfacep, dfacesz); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/acl_common.c:1644:11: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(aclentp + aclcnt, dfaclentp, dfaclsz); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/callb.c:61:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char c_name[CB_MAXNAME+1]; /* debug:max func name length */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:37:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char ce_prefix[CE_IGNORE][MAX_PREFIX_SIZE] = { "", "NOTICE: ", "WARNING: ", "ERROR: " }; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dirent.h:49:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char d_name[1]; /* name of file */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dirent.h:60:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char d_name[1]; /* name of file */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/dirent.h:74:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char d_name[1]; /* name of file */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/extdirent.h:51:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ed_name[1]; /* name of file */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/refstr_impl.h:48:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char rs_string[1]; /* constant string */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:68:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_basetype[FSTYPSZ]; /* target fs type name, */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:72:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_fstr[32]; /* filesystem-specific string */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:90:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_basetype[_FSTYPSZ]; /* target fs type name, */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:94:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_fstr[32]; /* filesystem-specific string */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:113:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_basetype[_FSTYPSZ]; /* target fs type name, */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:117:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_fstr[32]; /* filesystem-specific string */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:135:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_basetype[FSTYPSZ]; /* target fs type name, */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/statvfs.h:139:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char f_fstr[32]; /* filesystem-specific string */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/systm.h:67:3: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(to, from, maxlength - 1); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/taskq_impl.h:93:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tq_name[TASKQ_NAMELEN + 1]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vfs.h:168:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char data[MAXFIDSZ]; /* data (variable len) */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kcf_random.c:59:29: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VERIFY((random_fd = open("/dev/random", O_RDONLY)) != -1); // FIXME leaked fd data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kcf_random.c:69:30: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VERIFY((urandom_fd = open("/dev/urandom", O_RDONLY)) != -1); // FIXME leaked fd data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kmem.c:38:12: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/proc/self/status", "r"); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kmem.c:48:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[512]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kmem.c:49:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char key[100]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kobj_subr.c:45:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(src, dst + l1, copied); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:205:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char kstat_str[80]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:212:2: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(kstat_str,"%d\n",file->value.i32); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:221:2: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(kstat_str,"data type %d not handled\n",file->data_type); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:395:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mntdir[PATH_MAX]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:396:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(mntdir,"/zfs-kstat"); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:401:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char my_arg[512]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:403:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(my_arg,"fsname=kstat,nonempty,allow_other"); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/main.c:39:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char hw_serial[11]; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/pathname.c:174:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(sympnp->pn_path, pnp->pn_buf, sympnp->pn_pathlen); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/pathname.c:190:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(sympnp->pn_path, pnp->pn_path, sympnp->pn_pathlen); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/sid.c:57:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dom, res->kd_name, len); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:390:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(base->v_path, rpath, rpathlen); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:395:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(path, rpath + rpathlen, plen); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:452:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(src->v_path, buf, alloc); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:782:23: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VOPSTATS_UPDATE(vp, open); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:796:25: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VOPSTATS_UPDATE(*vpp, open); data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:520:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[UMEM_ENV_ITEM_MAX]; data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:539:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char outbuf[ENV_SHORT_BYTES + 1]; data/zfs-fuse-0.7.0/src/lib/libumem/init_lib.c:107:10: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char proc_stat[8192]; data/zfs-fuse-0.7.0/src/lib/libumem/init_lib.c:111:8: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). fd = open("/proc/stat", O_RDONLY); data/zfs-fuse-0.7.0/src/lib/libumem/init_lib.c:125:17: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). ncpus = atoi(cur + 3) + 1; data/zfs-fuse-0.7.0/src/lib/libumem/malloc.c:439:9: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(buf, buf_arg, MIN(newsize, oldsize)); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:70:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char umem_error_buffer[ERR_SIZE] = ""; data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:194:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[UMEM_MAX_ERROR_SIZE] = ""; data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:214:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[UMEM_MAX_ERROR_SIZE] = ""; data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:229:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[UMEM_MAX_ERROR_SIZE] = ""; data/zfs-fuse-0.7.0/src/lib/libumem/sol_compat.h:40:9: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. #define bcopy(s, d, n) memcpy(d, s, n) data/zfs-fuse-0.7.0/src/lib/libumem/sol_compat.h:40:26: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. #define bcopy(s, d, n) memcpy(d, s, n) data/zfs-fuse-0.7.0/src/lib/libumem/sys/vmem_impl_user.h:123:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vm_name[VMEM_NAMELEN]; /* arena name */ data/zfs-fuse-0.7.0/src/lib/libumem/umem.c:1128:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, logspace, size); data/zfs-fuse-0.7.0/src/lib/libumem/umem.c:2783:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[UMEM_CACHE_NAMELEN + 1]; data/zfs-fuse-0.7.0/src/lib/libumem/umem.c:2959:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&umem_null_cache_template, &umem_null_cache, data/zfs-fuse-0.7.0/src/lib/libumem/umem_agent_support.c:38:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char __umem_agent_stack_beg[AGENT_STACK_SIZE]; data/zfs-fuse-0.7.0/src/lib/libumem/umem_impl.h:262:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char cc_pad[UMEM_CPU_PAD]; /* for nice alignment (32-bit) */ data/zfs-fuse-0.7.0/src/lib/libumem/umem_impl.h:298:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char cache_name[UMEM_CACHE_NAMELEN + 1]; data/zfs-fuse-0.7.0/src/lib/libumem/umem_impl.h:355:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clh_pad[UMEM_CPU_CACHE_SIZE - data/zfs-fuse-0.7.0/src/lib/libumem/umem_test.c:15:3: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(foo, "hello there"); data/zfs-fuse-0.7.0/src/lib/libumem/umem_test2.c:19:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *testcases[N_TESTSTRINGS][N_TESTS + 1]; data/zfs-fuse-0.7.0/src/lib/libumem/vmem.c:1507:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[VMEM_NAMELEN + 21]; data/zfs-fuse-0.7.0/src/lib/libumem/vmem_mmap.c:66:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[80]; data/zfs-fuse-0.7.0/src/lib/libumem/vmem_mmap.c:67:15: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/proc/sys/vm/max_map_count","r"); data/zfs-fuse-0.7.0/src/lib/libumem/vmem_mmap.c:74:15: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). nb_mmap = atoi(buf); data/zfs-fuse-0.7.0/src/lib/libumem/vmem_mmap.c:82:15: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/proc/sys/vm/max_map_count","w"); data/zfs-fuse-0.7.0/src/lib/libuutil/include/libuutil_impl.h:112:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ulp_name[UU_LIST_POOL_MAXNAME]; data/zfs-fuse-0.7.0/src/lib/libuutil/include/libuutil_impl.h:158:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char uap_name[UU_AVL_POOL_MAXNAME]; data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c:65:11: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(buf, str, sz); data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c:74:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char attic[1]; data/zfs-fuse-0.7.0/src/lib/libuutil/uu_open.c:58:7: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). f = open(fname, O_CREAT | O_EXCL | O_RDWR, 0600); data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs.h:140:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char z_pname[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs.h:145:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char z_key[MAXPATHLEN]; /* name, such as joe */ data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs.h:153:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char z_setpoint[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs.h:357:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. extern const char *hist_event_table[LOG_END]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h:69:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char libzfs_action[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h:70:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char libzfs_desc[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h:83:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char libzfs_chassis_id[256]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h:91:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zfs_name[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/include/libzfs_impl.h:112:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zpool_name[ZPOOL_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:157:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char shareopts[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:288:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char newname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:393:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char property[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:394:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char where[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:491:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mounta[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:492:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountb[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:534:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char property[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:521:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:821:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char newpropname[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:822:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char domain[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1177:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1366:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1457:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1923:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2163:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2601:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2604:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2812:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2906:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2993:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3040:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3067:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3069:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3157:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3159:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3208:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3212:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3336:11: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). int fd = open("/proc/sys/vm/drop_caches", O_WRONLY, O_SYNC); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3502:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parent[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3504:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3711:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3983:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[ZFS_MAXNAMELEN+32]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:4024:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char lastsnapheld[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:4131:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[ZFS_MAXNAMELEN+32]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:4187:13: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). ncopies = atoi(strval); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c:195:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c:196:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char isa[257]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_graph.c:93:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zv_dataset[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:96:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) < 0) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:943:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:944:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path2[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:1118:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(cachefile, O_RDONLY)) < 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:129:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXPATHLEN], *tab; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:139:25: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). hdl->libzfs_sharetab = fopen("/var/lib/nfs/etab", "r"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:245:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sourceloc[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:278:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountpoint[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:279:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mntopts[MNT_LINE_MAX]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:333:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[256]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:552:15: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/var/lib/nfs/etab","r"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:556:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buff[2048]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:560:14: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). int t = atoi(s+5); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:587:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buff[2048]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:598:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char opts[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:603:7: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(opts,"ro"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:605:7: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(&opts[strlen(opts)],",fsid=%d",fsid); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:607:7: [2] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). Risk is low because the source is a constant string. strcat(opts,",no_subtree_check"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:634:15: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/var/lib/nfs/etab","r"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:636:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char buff[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:637:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char share[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:681:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buff[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:691:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char buff[80]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:692:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(buff,"share error %d",error); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:723:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:724:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char isa[MAXISALEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:903:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountpoint[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:904:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char shareopts[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:905:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sourcestr[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:1171:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountpoint[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:1233:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mounta[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:1234:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mountb[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:51:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char *hist_event_table[LOG_END] = { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:416:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char bootfs[ZPOOL_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:614:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:669:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[ZFS_MAXPROPLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:926:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:999:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1056:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1100:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1170:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1222:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1294:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char timestr[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1340:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char timestr[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1463:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1514:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char desc[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1601:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1840:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2030:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2031:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2041:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDWR | O_NDELAY)) < 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2073:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2145:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2195:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2230:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2284:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2477:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2575:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2785:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2830:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2898:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2955:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDONLY)) < 0) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3014:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3081:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char str[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3362:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[HIS_BUF_LEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3406:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dsname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3460:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char diskname[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3468:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(diskname, O_RDONLY|O_NDELAY)) >= 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3524:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3530:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3562:12: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((fd = open(path, O_RDWR | O_NDELAY)) < 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3605:9: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(vtoc->efi_parts[0].p_name, "zfs"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3672:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3673:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char poolname[ZPOOL_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:678:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char guidstring[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:834:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char prevsnap[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:868:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1040:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snapname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1143:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1148:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char holdtag[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1607:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1649:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char newname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1765:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1803:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1804:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tryname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1866:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tryname[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1931:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tofs[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1932:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sendfs[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1933:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2137:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2214:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2215:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char prop_errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2382:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char suffix[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2402:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char snap[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2542:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2706:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf1[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2707:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf2[64]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2730:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errbuf[1024]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2803:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nonpackage_sendfs[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_status.c:335:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char refcnt[6]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_status.c:336:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char blocks[6], lsize[6], psize[6], dsize[6]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_status.c:337:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ref_blocks[6], ref_lsize[6], ref_psize[6], ref_dsize[6]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_status.c:343:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(refcnt, "Total"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:596:25: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). hdl->libzfs_sharetab = fopen("/var/lib/nfs/etab", "r"); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:931:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[128]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c:112:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[CMSG_SPACE(sizeof(int))]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dbuf.h:311:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char __db_buf[32]; \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dbuf.h:314:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(__db_buf, "mdn"); \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/ddt.h:154:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ddt_op_name[32]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu.h:558:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dds_origin[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu_objset.h:54:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char os_pad[OBJSET_PHYS_SIZE - sizeof (dnode_phys_t)*3 - data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dnode.h:251:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char __db_buf[32]; \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dnode.h:254:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(__db_buf, "mdn"); \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dataset.h:153:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ds_snapname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dir.h:100:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dd_myname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/fs/zfs.h:134:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. extern const char *zfs_userquota_prop_prefixes[ZFS_NUM_USERQUOTA_PROPS]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/spa.h:624:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ha_zone[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/spa_impl.h:95:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char spa_name[MAXNAMELEN]; /* pool name */ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/txg_impl.h:41:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tc_pad[16]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h:73:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vdev_op_type[16]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h:221:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vp_nvlist[VDEV_PHYS_SIZE - sizeof (zio_eck_t)]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h:226:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vl_pad1[VDEV_PAD_SIZE]; /* 8K */ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h:227:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vl_pad2[VDEV_PAD_SIZE]; /* 8K */ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/vdev_impl.h:229:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char vl_uberblock[VDEV_UBERBLOCK_RING]; /* 128K */ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap.h:311:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char za_name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap_impl.h:54:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mze_name[MZAP_NAME_LEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zap_impl.h:178:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zn_normbuf[ZAP_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:174:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char drr_toname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:246:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zi_func[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:276:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zc_name[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:277:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zc_value[MAXPATHLEN * 2]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:278:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zc_string[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:279:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zc_top_ds[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zfs_ioctl.h:304:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zu_domain[256]; data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/zio.h:229:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. extern char *zio_type_name[ZIO_TYPES]; data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:534:11: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char pad[(HT_LOCK_PAD - sizeof (kmutex_t))]; data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:1273:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(from->b_data, buf->b_data, size); data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:2426:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(buf->b_data, arg, buf->b_hdr->b_size); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:479:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(DN_BONUS(dn->dn_phys), db->db.db_data, bonuslen); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:670:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(db->db.db_data, dr->dt.dl.dr_data, DN_MAX_BONUSLEN); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:676:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(db->db.db_data, dr->dt.dl.dr_data->b_data, size); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:875:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(obuf->b_data, buf->b_data, MIN(osize, size)); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:1342:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(buf->b_data, db->db.db_data, db->db.db_size); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:1747:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dr->dt.dl.dr_data->b_data, db->db.db_data, data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:2062:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(*datap, DN_BONUS(dn->dn_phys), dn->dn_phys->dn_bonuslen); data/zfs-fuse-0.7.0/src/lib/libzpool/dbuf.c:2118:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(db->db.db_data, (*datap)->b_data, blksz); data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:43:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char *ddt_class_name[DDT_CLASSES] = { data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:57:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[DDT_NAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:80:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[DDT_NAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:100:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[DDT_NAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:134:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[DDT_NAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:566:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(src, dst, s_len); data/zfs-fuse-0.7.0/src/lib/libzpool/ddt.c:584:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(src, dst, d_len); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:589:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((char *)db->db_data + bufoff, buf, tocpy); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:631:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(buf, (char *)db->db_data + bufoff, tocpy); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:796:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(va, (char *)db->db_data + bufoff, thiscpy); data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:260:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(os->os_phys_buf->b_data, buf->b_data, data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:748:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char failed[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:1073:15: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char zerobuf[DN_MAX_BONUSLEN] = {0}; data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_send.c:454:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char clonelastname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_send.c:994:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, db->db_data, drro->drr_bonuslen); data/zfs-fuse-0.7.0/src/lib/libzpool/dnode_sync.c:69:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dn->dn_phys->dn_blkptr, db->db.db_data, data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:654:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(name, "mos"); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2198:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char failed[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:3270:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char failed[MAXPATHLEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:129:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char idstr[32]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:316:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char source[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:370:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char p_setname[ZFS_MAX_DELEG_NAME]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:402:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char whokey[ZFS_MAX_DELEG_NAME]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:471:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char whokey[ZFS_MAX_DELEG_NAME]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_deleg.c:659:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char whokey[ZFS_MAX_DELEG_NAME]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:289:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:536:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:413:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char setpoint[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:564:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char valbuf[32]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:897:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[ZAP_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:1017:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char setpoint[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/flushwc.c:48:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char sense_b[32]; data/zfs-fuse-0.7.0/src/lib/libzpool/flushwc.c:49:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char cmdp[10]; data/zfs-fuse-0.7.0/src/lib/libzpool/flushwc.c:109:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char ata_command[4]; data/zfs-fuse-0.7.0/src/lib/libzpool/gzip.c:50:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(s_start, d_start, s_len); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:47:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char hw_serial[HW_HOSTID_LEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:631:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char ce_prefix[CE_IGNORE][10] = { "", "NOTICE: ", "WARNING: ", "" }; data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:632:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char ce_suffix[CE_IGNORE][2] = { "", "\n", "\n", "" }; data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:814:22: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VERIFY((random_fd = open("/dev/random", O_RDONLY)) != -1); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:815:23: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). VERIFY((urandom_fd = open("/dev/urandom", O_RDONLY)) != -1); data/zfs-fuse-0.7.0/src/lib/libzpool/metaslab.c:1001:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(smo, db->db_data, sizeof (*smo)); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:92:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char *const zio_taskq_types[ZIO_TASKQ_TYPES] = { data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:579:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&spa->spa_errlist_last, last, sizeof (avl_tree_t)); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:580:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&spa->spa_errlist_scrub, scrub, sizeof (avl_tree_t)); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:618:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; data/zfs-fuse-0.7.0/src/lib/libzpool/spa_errlog.c:333:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[64]; data/zfs-fuse-0.7.0/src/lib/libzpool/spa_history.c:123:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[sizeof (reclen)]; data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c:1108:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(s, new, len); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:55:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%llu", (u_longlong_t)n); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:57:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%.2f%c", data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:60:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%.1f%c", data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:63:10: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%llu%c", (u_longlong_t)n, u); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:76:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char used[6], avail[6]; data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:77:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char rops[6], wops[6], rbytes[6], wbytes[6], rerr[6], werr[6], cerr[6]; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:197:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(pvd->vdev_child, newchild, oldsize); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:832:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(vd->vdev_ms, mspp, oldc * sizeof (*mspp)); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:854:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(db->db_data, &smo, sizeof (smo)); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:1718:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(db->db_data, smo, sizeof (*smo)); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:1787:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(smo, db->db_data, sizeof (*smo)); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:2413:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(&vd->vdev_stat, vs, sizeof (*vs)); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:2850:8: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static char old_name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:3041:6: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char cmd[2048]; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_cache.c:201:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(ve->ve_data + cache_phase, zio->io_data, zio->io_size); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_cache.c:350:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((char *)zio->io_data + start - io_start, data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_file.c:83:6: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char path[64]; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_mirror.c:192:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zio->io_data, pio->io_data, pio->io_size); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_queue.c:159:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((char *)aio->io_data + (pio->io_offset - data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_queue.c:304:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dio->io_data, (char *)aio->io_data + data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c:325:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *bad_parity[VDEV_RAIDZ_MAXPARITY]; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c:421:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(col->rc_data, buf, col->rc_size); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c:1667:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(rc->rc_data, orig[c], rc->rc_size); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c:1784:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(rc->rc_data, orig[i], rc->rc_size); data/zfs-fuse-0.7.0/src/lib/libzpool/vdev_raidz.c:1815:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(orig[i], rc->rc_data, rc->rc_size); data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c:980:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[20]; data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c:989:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[20]; data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c:998:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[20]; data/zfs-fuse-0.7.0/src/lib/libzpool/zap.c:1008:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[20]; data/zfs-fuse-0.7.0/src/lib/libzpool/zap_leaf.c:304:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(la->la_array, p, ZAP_LEAF_ARRAY_BYTES); data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:153:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char norm[ZAP_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:535:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zap->zap_dbuf->db_data, mzp, sz); data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fm.c:116:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char class[64]; data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fm.c:715:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(info, report->zcr_ckinfo, sizeof (*info)); data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fm.c:833:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char class[64]; data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c:912:10: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. (void) memcpy(zp->z_phys + 1, xoap->xoa_av_scanstamp, data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c:1688:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char component[MAXNAMELEN + 2]; data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c:1704:11: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(component + 1, "<xattrdir>"); data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c:1715:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(component, path, complen); data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:206:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(lr, dst, len); data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:220:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(lr, dst, zilc->zc_nused); data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:262:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(abuf->b_data, wbuf, arc_buf_size(abuf)); data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:983:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(lrc, lr_buf, reclen); data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:1578:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/lib/libzpool/zil.c:1630:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(lr, zr->zr_lr, reclen); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:70:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *zio_type_name[ZIO_TYPES] = { data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:139:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[36]; data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:140:11: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(name, "zio_buf_%lu", (ulong_t)size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:145:11: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(name, "zio_data_buf_%lu", (ulong_t)size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:305:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zio->io_data, data, size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:785:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data, wbuf, size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:1827:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dde->dde_repair_data, zio->io_data, zio->io_size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:2259:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zio->io_data, abuf, zio->io_size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:2371:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zio->io_data, buf, zio->io_size); data/zfs-fuse-0.7.0/src/lib/libzpool/zio.c:2686:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zio->io_data, abuf, psize); data/zfs-fuse-0.7.0/src/zfs-fuse/cmd_listener.c:183:9: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(&job,item,sizeof(ioctl_queue_item_t)); data/zfs-fuse-0.7.0/src/zfs-fuse/fuse_listener.c:65:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *mountpoints[MAX_FDS]; data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:326:29: [2] (integer) atol: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). arg_min_uberblock_txg = atol(optarg); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:356:12: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen("/etc/zfs/zfsrc","r"); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:360:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[1024]; data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:362:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *argv[10]; data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c:109:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char fname[100]; data/zfs-fuse-0.7.0/src/zfs-fuse/ptrace.c:114:14: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *ret = fopen(fname, "a"); data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:99:19: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). lock_fd = open(LOCKFILE, O_WRONLY); data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:168:17: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). devnull=open("/dev/null",O_RDWR); /* handle standard I/O */ data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:195:13: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). FILE *f = fopen(pidfile, "w"); data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:339:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char real_opts[1024]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c:968:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(zp->z_phys->zp_acl.z_ace_data, aclnode->z_acldata, data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c:1134:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(aclnode->z_acldata, start, aclnode->z_size); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c:1773:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data1, data2, data2sz); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c:1817:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(data1, data2, data1sz); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_acl.c:2049:5: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(aclnode->z_acldata, start, data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_dir.c:277:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dl->dl_name, name, dl->dl_namesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:119:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[256]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:344:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ds_hexsl[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:455:4: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char setpoint[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:650:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parentname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:685:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parentname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:757:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parentname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:2664:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char parentname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3384:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tofs[ZFS_MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:169:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(xoap->xoa_av_scanstamp, scanstamp, AV_SCANSTAMP_SZ); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:199:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy((void *)zdomain->z_domain, start, data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:318:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(vsecp->vsa_aclentp, end, aclsize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:330:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, end, namesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:355:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, (char *)(lr + 1), namesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:380:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, (char *)(lr + 1), namesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:413:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(name, (char *)(lr + 1), namesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:414:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(link, (char *)(lr + 1) + namesize, linksize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:441:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(sname, (char *)(lr + 1), snamesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:442:2: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(dname, (char *)(lr + 1) + snamesize, dnamesize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:669:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(vsecp->vsa_aclentp, (ace_t *)(lrv0 + 1), aclbytes); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:673:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(vsecp->vsa_aclentp, start, aclbytes); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:255:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[DIRENT64_RECLEN(MAXNAMELEN)]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:695:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[DIRENT64_RECLEN(MAXNAMELEN)]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:993:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buffer[PATH_MAX + 1]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_replay.c:129:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(scanstamp, xoap->xoa_av_scanstamp, AV_SCANSTAMP_SZ); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:505:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char osname[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:592:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[32]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:718:9: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%llx", (longlong_t)fuid); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:726:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[32]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:753:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[32]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:813:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[32]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:823:9: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. (void) sprintf(buf, "%llx", (longlong_t)fuid); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:1319:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ds_hexsl[MAXNAMELEN]; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2066:11: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(zap.za_name, ".."); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3512:4: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(link, zp->z_phys + 1, len); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3531:3: [2] (buffer) bcopy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. bcopy(link, dbp->db_data, len); data/zfs-fuse-0.7.0/src/zfs-fuse/zfsfuse_socket.c:293:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[CMSG_SPACE(sizeof(int))]; data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:107:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char zv_name[MAXPATHLEN]; /* pool/dd name */ data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:461:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char chrbuf[30], blkbuf[30]; data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:548:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char nmbuf[20]; data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:1478:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(dki.dki_cname, "zvol"); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:1479:10: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. (void) strcpy(dki.dki_dname, "zvol"); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:840:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) sprintf(blkbuf + strlen(blkbuf), "%llu:%llx:%llx ", data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:845:26: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) sprintf(blkbuf + strlen(blkbuf), data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1312:25: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) snprintf(aux + strlen(aux), sizeof (aux), " (K=%s)", data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1317:25: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) snprintf(aux + strlen(aux), sizeof (aux), " (Z=%s)", data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1423:34: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) sprintf_blkptr(blkbuf + strlen(blkbuf), os->os_rootbp); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1551:6: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). if (read(fd, buf, statbuf.st_size) != statbuf.st_size) { data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:1604:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(dev) + 1; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2438:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). q = &vc->vdev_path[strlen(vc->vdev_path) - 2]; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2740:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int sz = 1 + strlen(name) + ((sepp) ? strlen(sepp) : 0); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb.c:2740:41: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int sz = 1 + strlen(name) + ((sepp) ? strlen(sepp) : 0); data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:71:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). link = name + strlen(name) + 1; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:108:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *tnm = snm + strlen(snm) + 1; data/zfs-fuse-0.7.0/src/cmd/zdb/zdb_il.c:316:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). sprintf_blkptr(blkbuf + strlen(blkbuf), bp); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_iter.c:160:35: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). col->sc_user_prop = safe_malloc(strlen(name) + 1); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:823:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strncmp(tname, name, strlen(tname)) == 0 && data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:824:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (name[strlen(tname)] == '/' || name[strlen(tname)] == '@')) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:824:42: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (name[strlen(tname)] == '/' || name[strlen(tname)] == '@')) { data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:1383:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). fake_name.pl_width = strlen(gettext("NAME")); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:2820:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(parent, path, delim - path); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3240:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(mntopts); data/zfs-fuse-0.7.0/src/cmd/zfs/zfs_main.c:3243:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (len + 1 + strlen(newopts) >= MNT_LINE_MAX) { data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:981:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(name) + depth > max) data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:982:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). max = strlen(name) + depth; data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2029:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(name) + depth > cb->cb_namewidth) data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2033:32: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (int)(cb->cb_namewidth - strlen(name) - depth), ""); data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:2169:23: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cb->cb_namewidth = strlen(zpool_get_name(zhp)); data/zfs-fuse-0.7.0/src/cmd/zpool/zpool_main.c:4181:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). fake_name.pl_width = strlen(gettext("NAME")); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:389:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) vsprintf(buf + strlen(buf), message, args); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:392:25: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) snprintf(buf + strlen(buf), FATAL_MSG_SZ - strlen(buf), data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:392:53: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) snprintf(buf + strlen(buf), FATAL_MSG_SZ - strlen(buf), data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:410:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). for (i = 0; i < strlen(ends); i++) { data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:414:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (i == strlen(ends)) { data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:619:6: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). if (read(ztest_random_fd, &r, sizeof (r)) != sizeof (r)) data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1103:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1120:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1698:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = name ? strlen(name) + 1 : 0; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:1711:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = name ? strlen(name) + 1 : 0; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:2480:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). newpath[strlen(newpath) - 1] = 'b'; data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4667:23: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). newname = umem_alloc(strlen(oldname) + 5, UMEM_NOFAIL); data/zfs-fuse-0.7.0/src/cmd/ztest/ztest.c:4702:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). umem_free(newname, strlen(newname) + 1); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:443:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). return (strlen(NVP_NAME(nvp)) == nvp->nvp_name_sz - 1 ? 0 : EFAULT); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:765:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). value_sz = strlen(data) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:808:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). value_sz += strlen(strs[i]) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:902:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). name_sz = strlen(name) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:926:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int slen = strlen(strs[i]) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:1684:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). n = strlen(np); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:1715:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (strlen(nvpair_name(nvp)) != n)) data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:2641:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). buf += strlen(buf) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:2929:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). nvp->nvp_name_sz = strlen(buf) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:3081:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(buf) + 1; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:3101:42: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). uint64_t nvp_sz = 4 + 4 + 4 + NV_ALIGN4(strlen(NVP_NAME(nvp))) + 4 + 4; data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:3128:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). nvp_sz += 4 + NV_ALIGN4(strlen((char *)NVP_VALUE(nvp))); data/zfs-fuse-0.7.0/src/lib/libnvpair/nvpair.c:3155:28: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). nvp_sz += 4 + NV_ALIGN4(strlen(strs[i])); data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mount.h:62:25: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *newspec = malloc(strlen(spec) + strlen(FUSESPEC) + 1); data/zfs-fuse-0.7.0/src/lib/libsolcompat/include/sys/mount.h:62:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *newspec = malloc(strlen(spec) + strlen(FUSESPEC) + 1); data/zfs-fuse-0.7.0/src/lib/libsolcompat/mkdirp.c:171:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). mbPathlen = strlen(mbPath); data/zfs-fuse-0.7.0/src/lib/libsolcompat/strlcat.c:45:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t l2 = strlen(src); data/zfs-fuse-0.7.0/src/lib/libsolcompat/strlcpy.c:41:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t slen = strlen(src); data/zfs-fuse-0.7.0/src/lib/libsolcompat/u8_textprep.c:1884:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). n1 = strlen(s1); data/zfs-fuse-0.7.0/src/lib/libsolcompat/u8_textprep.c:1885:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). n2 = strlen(s2); data/zfs-fuse-0.7.0/src/lib/libsolcompat/zone.c:51:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). ssize_t ret = strlen(GLOBAL_ZONEID_NAME) + 1; data/zfs-fuse-0.7.0/src/lib/libsolcompat/zone.c:56:2: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). strncpy(buf, GLOBAL_ZONEID_NAME, buflen); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/callb.c:134:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(name) > CB_MAXNAME) data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/callb.c:139:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(cp->c_name, name, CB_MAXNAME); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:43:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int slen = strlen(fmt) + MAX_PREFIX_SIZE + 1; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/cmn_err.c:75:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). slen = strlen(fmt) + MAX_PREFIX_SIZE + 1; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/systm.h:65:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t length = strlen(from); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vnode.h:314:128: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). extern int vn_open(char *pnamep, enum uio_seg seg, int filemode, int createmode, struct vnode **vpp, enum create crwhy, mode_t umask); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vnode.h:315:130: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). extern int vn_openat(char *pnamep, enum uio_seg seg, int filemode, int createmode, struct vnode **vpp, enum create crwhy, mode_t umask, struct vnode *startvp, int fd); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/vnode.h:316:137: [1] (obsolete) ulimit: This C routine is considered obsolete (as opposed to the shell command by the same name, which is NOT obsolete) (CWE-676). Use getrlimit(2), setrlimit(2), and sysconf(3) instead. extern int vn_rdwr(enum uio_rw rw, struct vnode *vp, caddr_t base, ssize_t len, offset_t offset, enum uio_seg seg, int ioflag, rlim64_t ulimit, cred_t *cr, ssize_t *residp); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/include/sys/zfs_context.h:73:39: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). #define strfree(str) kmem_free((str), strlen(str)+1) data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kcf_random.c:45:11: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). bytes = read(fd, ptr, resid); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kobj_subr.c:35:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t l2 = strlen(src); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:240:19: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). stbuf->st_size = strlen(kstat_str); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/kstat.c:372:36: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). reply_buf_limited(req, kstat_str, strlen(kstat_str), off, size); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/refstr.c:41:3: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(str) + 1; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/sid.c:50:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t len = strlen(dom) + 1; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/taskq.c:1635:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(tq->tq_name, name, TASKQ_NAMELEN + 1); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:367:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). rpathlen = strlen(base->v_path); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:385:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (base->v_path == NULL || strlen(base->v_path) != rpathlen) { data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:423:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(tmp, strlen(tmp) + 1); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:441:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). alloc = strlen(src->v_path) + 1; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:447:29: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (src->v_path == NULL || strlen(src->v_path) + 1 != alloc) { data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:545:15: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). old_umask = umask(0); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:562:10: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). (void) umask(old_umask); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:574:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *realpath = kmem_alloc(strlen(path) + 2, KM_SLEEP); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:583:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(realpath, strlen(path) + 2); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:600:11: [1] (obsolete) ulimit: This C routine is considered obsolete (as opposed to the shell command by the same name, which is NOT obsolete) (CWE-676). Use getrlimit(2), setrlimit(2), and sysconf(3) instead. rlim64_t ulimit, /* meaningful only if rw is UIO_WRITE */ data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:621:19: [1] (obsolete) ulimit: This C routine is considered obsolete (as opposed to the shell command by the same name, which is NOT obsolete) (CWE-676). Use getrlimit(2), setrlimit(2), and sysconf(3) instead. uio.uio_llimit = ulimit; data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:855:25: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). VOPSTATS_UPDATE_IO(vp, read, data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:963:39: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). vn_setpath(rootdir, dvp, *vpp, nm, strlen(nm)); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:1008:41: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). vn_setpath(rootdir, dvp, *vpp, name, strlen(name)); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:1034:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(dirname)); data/zfs-fuse-0.7.0/src/lib/libsolkerncompat/vnode.c:1335:18: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). ssize_t iolen = read(vp->v_fd, uiop->uio_iov->iov_base, uiop->uio_iov->iov_len); data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:543:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(outbuf, beg, ENV_SHORT_BYTES); data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:551:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, beg, count); data/zfs-fuse-0.7.0/src/lib/libumem/envvar.c:709:26: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). next = end = value + strlen(value); data/zfs-fuse-0.7.0/src/lib/libumem/init_lib.c:113:23: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). const ssize_t n = read(fd, proc_stat, sizeof(proc_stat) - 1); data/zfs-fuse-0.7.0/src/lib/libumem/malloc.c:163:1: [1] (free) memalign: On some systems (though not Linux-based systems) an attempt to free() results from memalign() may fail. This may, on a few systems, be exploitable. Also note that memalign() may not check that the boundary parameter is correct (CWE-676). Use posix_memalign instead (defined in POSIX's 1003.1d). Don't switch to valloc(); it is marked as obsolete in BSD 4.3, as legacy in SUSv2, and is no longer defined in SUSv3. In some cases, malloc()'s alignment may be sufficient. memalign(size_t align, size_t size_arg) data/zfs-fuse-0.7.0/src/lib/libumem/malloc.c:247:10: [1] (free) memalign: On some systems (though not Linux-based systems) an attempt to free() results from memalign() may fail. This may, on a few systems, be exploitable. Also note that memalign() may not check that the boundary parameter is correct (CWE-676). Use posix_memalign instead (defined in POSIX's 1003.1d). Don't switch to valloc(); it is marked as obsolete in BSD 4.3, as legacy in SUSv2, and is no longer defined in SUSv3. In some cases, malloc()'s alignment may be sufficient. return (memalign(pagesize, size)); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:118:39: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) write(UMEM_ERRFD, error_str, strlen(error_str)); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:204:33: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) write(UMEM_ERRFD, buf, strlen(buf)); data/zfs-fuse-0.7.0/src/lib/libumem/misc.c:222:32: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) write(UMEM_ERRFD, buf, strlen(buf)); data/zfs-fuse-0.7.0/src/lib/libumem/umem.c:2557:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(cp->cache_name, name, sizeof (cp->cache_name) - 1); data/zfs-fuse-0.7.0/src/lib/libumem/umem_fail.c:137:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (format[strlen(format)-1] != '\n') data/zfs-fuse-0.7.0/src/lib/libumem/umem_fail.c:160:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (format[strlen(format)-1] != '\n') data/zfs-fuse-0.7.0/src/lib/libumem/umem_test2.c:29:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len[i] = strlen(TESTSTRINGS[i]) + 1; data/zfs-fuse-0.7.0/src/lib/libuutil/uu_alloc.c:62:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). sz = strlen(str) + 1; data/zfs-fuse-0.7.0/src/lib/libuutil/uu_ident.c:95:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). const char *end = name + strlen(name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:266:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(parent); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_changelist.c:304:52: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) strcat(newname, cn->cn_handle->zfs_name + strlen(src)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:792:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(nvpair_name(elem)) >= ZAP_MAXNAMELEN) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:1937:31: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). relpath = zhp->zfs_name + strlen(source); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2253:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(zfs_userquota_prop_prefixes[type])) == 0) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2355:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_name, zhp->zfs_name, sizeof (zc.zc_name)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2560:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t d1len = strlen(ds1); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2563:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(ds2) < d1len) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2582:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, path, MIN(buflen, loc - path)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2619:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). slash = parent + strlen(parent); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2620:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_name, parent, slash - parent); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:2670:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). *prefixlen = strlen(parent); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3236:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(parent, path, delim - path); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3754:23: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_width = strlen(nvpair_name(elem)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3771:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(buf) > entry->pl_width) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3772:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_width = strlen(buf); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3777:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(buf) > entry->pl_recvd_width) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3778:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_recvd_width = strlen(buf); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3784:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(strval) > entry->pl_width) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3785:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_width = strlen(strval); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3790:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(buf) > entry->pl_recvd_width) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3791:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_recvd_width = strlen(buf); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_dataset.c:3939:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_name, zhp->zfs_name, sizeof (zc.zc_name)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c:364:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_name, zhp->zpool_name, sizeof (zc.zc_name)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c:365:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_value, fru, sizeof (zc.zc_value)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_fru.c:415:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(hdl->libzfs_chassis_id); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_graph.c:167:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). assert(strlen(dataset) < ZFS_MAXNAMELEN); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_graph.c:594:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(zgv->zv_dataset) + 1)) == NULL) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:165:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). src = ne->ne_name + strlen(ne->ne_name) - 1; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:166:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). dst = path + strlen(path) - 1; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:977:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). end = &path[strlen(path)]; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_import.c:1138:6: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). if (read(fd, buf, statbuf.st_size) != statbuf.st_size) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:320:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). MNTTYPE_ZFS, NULL, 0, mntopts, strlen (mntopts)) != 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:605:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). sprintf(&opts[strlen(opts)],",fsid=%d",fsid); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:641:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). memmove(s+4,s+1,strlen(s+1)+1); // moves what's after the space data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:642:2: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). Risk is low because the source is a constant string. strncpy(s,"\\040",4); // replaces the space with \040 (encoded space) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_mount.c:1362:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). namelen = strlen(zhp->zpool_name); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:377:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(pool); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:682:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(buf) > entry->pl_width) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:683:23: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_width = strlen(buf); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1688:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(srchval) == strlen(val) - 2 && data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1688:28: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(srchval) == strlen(val) - 2 && data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1689:31: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strncmp(srchval, val, strlen(srchval)) == 0) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1715:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strncmp(val, type, strlen(val)) != 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1721:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(VDEV_TYPE_RAIDZ)) == 0 || data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1723:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(VDEV_TYPE_MIRROR)) == 0); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1830:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strncmp(name, VDEV_TYPE_RAIDZ, strlen(VDEV_TYPE_RAIDZ)) == 0 || data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:1831:38: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strncmp(name, VDEV_TYPE_MIRROR, strlen(VDEV_TYPE_MIRROR)) == 0) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2116:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). pathname += strlen(DISK_ROOT) + 1; data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2982:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_name, zhp->zpool_name, sizeof (zc.zc_name)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:2983:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(zc.zc_value, path, sizeof (zc.zc_value)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3235:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(history_str) + 1 + strlen(argv[i]) > data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3235:33: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(history_str) + 1 + strlen(argv[i]) > data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3252:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(history_str) > HIS_MAX_RECORD_LEN) data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3674:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int pathlen = strlen(ZVOL_FULL_DEV_DIR); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_pool.c:3702:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(poolname, volname, p - volname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1361:8: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). rv = read(fd, cp, len); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1453:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(newname, name, baselen); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1774:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(fsname)+1, newname, flags); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1812:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(fsname)+1, newname, flags); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1828:38: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). error = recv_destroy(hdl, fsname, strlen(tofs)+1, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:1895:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(tofs)+1, newname, flags); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2291:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(drrb->drr_toname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2319:35: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). chopprefix = drrb->drr_toname + strlen(sendfs); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2328:35: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). chopprefix = drrb->drr_toname + strlen(drrb->drr_toname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2333:42: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). ASSERT(chopprefix <= drrb->drr_toname + strlen(drrb->drr_toname)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2342:9: [1] (buffer) strncat: Easily used incorrectly (e.g., incorrectly computing the correct maximum size to add) [MS-banned] (CWE-120). Consider strcat_s, strlcat, snprintf, or automatically resizing strings. (void) strncat(zc.zc_value, chopprefix, sizeof (zc.zc_value)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_sendrecv.c:2502:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). create_parents(hdl, zc.zc_value, strlen(tosnap)) != 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:654:44: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (path[0] != '/' && strncmp(path, "./", strlen("./")) != 0) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:815:36: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbp->cb_colwidths[GET_COL_NAME] = strlen(dgettext(TEXT_DOMAIN, "NAME")); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:816:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbp->cb_colwidths[GET_COL_PROPERTY] = strlen(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:818:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbp->cb_colwidths[GET_COL_VALUE] = strlen(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:820:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbp->cb_colwidths[GET_COL_RECVD] = strlen(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:822:38: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbp->cb_colwidths[GET_COL_SOURCE] = strlen(dgettext(TEXT_DOMAIN, data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:846:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(propname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:850:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(pl->pl_user_prop); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:879:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(dgettext(TEXT_DOMAIN, "inherited from")); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:1018:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). for (i = 0; i < strlen(ends); i++) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:1022:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (i == strlen(ends)) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:1159:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(*svalp) >= ZFS_MAXPROPLEN) { data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:1270:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). entry->pl_width = strlen(propname); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_util.c:1319:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(props); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c:56:2: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). strncpy(name.sun_path, pathname, sizeof(name.sun_path)); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c:167:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t length = strlen((char *)(uintptr_t) cmd.cmd_u.copy_req.ptr); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c:206:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). uint32_t speclen = strlen(spec); data/zfs-fuse-0.7.0/src/lib/libzfs/libzfs_zfsfuse.c:207:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). uint32_t dirlen = strlen(dir); data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dmu.h:364:26: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). uint64_t length, int read, void *tag, int *numbufsp, dmu_buf_t ***dbpp); data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dir.h:149:44: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *__ds_name = kmem_alloc(MAXNAMELEN + strlen(MOS_DIR_NAME) + 1, \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/include/sys/dsl_dir.h:153:36: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(__ds_name, MAXNAMELEN + strlen(MOS_DIR_NAME) + 1); \ data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_namecheck.c:69:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(path) >= MAXNAMELEN) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_namecheck.c:102:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(path) >= ZFS_PERMSET_MAXLEN) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_namecheck.c:147:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(path) >= MAXNAMELEN) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_namecheck.c:307:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(pool) >= MAXNAMELEN) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_prop.c:409:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). for (i = 0; i < strlen(name); i++) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zfs_prop.c:435:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(zfs_userquota_prop_prefixes[prop])) == 0) { data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:213:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (len == strlen(propname) && data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:218:32: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (colname == NULL || len != strlen(colname)) data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:241:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (propname_match(data->propname, strlen(data->propname), data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:388:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). ret = strlen(pd->pd_colname); data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:412:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(idx[i].pi_name) > ret) data/zfs-fuse-0.7.0/src/lib/libzfscommon/zprop_common.c:413:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). ret = strlen(idx[i].pi_name); data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:918:6: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. int equal; data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:925:10: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. return (equal); data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:3961:6: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. int equal; data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:3982:6: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. if (equal && zio->io_error == 0 && !HDR_L2_EVICTED(hdr)) { data/zfs-fuse-0.7.0/src/lib/libzpool/arc.c:3999:8: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. if (!equal) data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:189:9: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). int read, void *tag, int *numbufsp, dmu_buf_t ***dbpp, uint32_t flags) data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:240:7: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). if (read) { data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:258:6: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). if (read) { data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:282:26: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). uint64_t length, int read, void *tag, int *numbufsp, dmu_buf_t ***dbpp) data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:291:56: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). err = dmu_buf_hold_array_by_dnode(dn, offset, length, read, tag, data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:301:26: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). uint64_t length, int read, void *tag, int *numbufsp, dmu_buf_t ***dbpp) data/zfs-fuse-0.7.0/src/lib/libzpool/dmu.c:306:56: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). err = dmu_buf_hold_array_by_dnode(dn, offset, length, read, tag, data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:1278:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(attr.za_name) + 1 > namelen) { data/zfs-fuse-0.7.0/src/lib/libzpool/dmu_objset.c:1317:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(attr.za_name) + 1 > namelen) { data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:659:11: [1] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). Risk is low because the source is a constant character. (void) strcat(name, "@"); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:689:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). result += strlen(ds->ds_snapname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:692:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). result += strlen(ds->ds_snapname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:1879:36: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (dsl_dataset_namelen(ds) + 1 + strlen(snapname) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2159:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (dsl_dir_namelen(ds->ds_dir) + 1 + strlen(newsnapname) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2249:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(oldname) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2301:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(oldname) + delta >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2321:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int delta = strlen(newname) - strlen(oldname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2321:33: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int delta = strlen(newname) - strlen(oldname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:2795:11: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(conflsnap, pa.err_ds, MAXNAMELEN); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dataset.c:3307:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(htag) + MAX_TAG_PREFIX_LEN >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:192:10: [1] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). Risk is low because the source is a constant character. (void) strcat(buf, "/"); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:223:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). result += strlen(dd->dd_myname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:226:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). result += strlen(dd->dd_myname); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:253:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(path) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:260:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(component, path, p - path); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_dir.c:272:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(component, path, p - path); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:62:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, zfs_prop_default_string(prop), data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:255:33: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). cbr->cbr_propname = kmem_alloc(strlen(propname)+1, KM_SLEEP); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:466:38: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free((void*)cbr->cbr_propname, strlen(cbr->cbr_propname)+1); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:753:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). psa.psa_numints = strlen(psa.psa_value) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:796:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(propname) >= ZAP_MAXNAMELEN) data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:845:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(nvpair_name(elem)) >= ZAP_MAXNAMELEN) { data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:852:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(valstr) >= (version < data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_prop.c:922:11: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, za.za_name, (suffix - za.za_name)); data/zfs-fuse-0.7.0/src/lib/libzpool/dsl_scrub.c:1051:7: [1] (buffer) equal: Function does not check the second iterator for over-read conditions (CWE-126). This function is often discouraged by most C++ coding standards in favor of its safer alternatives provided since C++14. Consider using a form of this function that checks the second iterator before potentially overflowing it. int equal; data/zfs-fuse-0.7.0/src/lib/libzpool/include/sys/zfs_context.h:516:39: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). #define strfree(str) kmem_free((str), strlen(str)+1) data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:400:15: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). old_umask = umask(0); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:415:10: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). (void) umask(old_umask); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:441:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *realpath = umem_alloc(strlen(path) + 2, UMEM_NOFAIL); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:450:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). umem_free(realpath, strlen(path) + 2); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:525:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(string); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:556:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen("debug="); data/zfs-fuse-0.7.0/src/lib/libzpool/kernel.c:753:11: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). bytes = read(fd, ptr, resid); data/zfs-fuse-0.7.0/src/lib/libzpool/kmem_asprintf.h:8:39: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). #define strfree(str) kmem_free((str), strlen(str)+1) data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:264:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). MAXNAMELEN + strlen(MOS_DIR_NAME) + 1, data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:278:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). MAXNAMELEN + strlen(MOS_DIR_NAME) + 1); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:3595:33: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). oldvd->vdev_path = kmem_alloc(strlen(newvd->vdev_path) + 5, data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:3761:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(vd->vdev_path); data/zfs-fuse-0.7.0/src/lib/libzpool/spa.c:4997:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). 1, strlen(strval) + 1, strval, tx) == 0); data/zfs-fuse-0.7.0/src/lib/libzpool/spa_errlog.c:350:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). *obj, buf, 1, strlen(name) + 1, name, tx); data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c:1106:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). len = strlen(s); data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c:1117:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(s, strlen(s) + 1); data/zfs-fuse-0.7.0/src/lib/libzpool/spa_misc.c:1225:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, spa->spa_root, buflen); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:112:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (int) (indent + strlen(prefix) - 25 - (vs->vs_space ? 0 : 12)), data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:129:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). tname = calloc(1, strlen(cname) + 2); data/zfs-fuse-0.7.0/src/lib/libzpool/util.c:132:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). tname[strlen(tname)] = '0' + np; data/zfs-fuse-0.7.0/src/lib/libzpool/vdev.c:1056:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(ZVOL_DIR)) == 0) data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:136:10: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). inlen = strlen(name) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:179:28: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). zn->zn_key_orig_numints = strlen(zn->zn_key_orig) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:187:29: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). zn->zn_key_norm_numints = strlen(zn->zn_key_norm) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:970:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(key) >= MZAP_NAME_LEN) { data/zfs-fuse-0.7.0/src/lib/libzpool/zap_micro.c:1037:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(name) >= MZAP_NAME_LEN) { data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_fuid.c:462:29: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). fuidp->z_domain_str_sz += strlen(domain) + 1; data/zfs-fuse-0.7.0/src/lib/libzpool/zfs_znode.c:1712:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). complen = strlen(component); data/zfs-fuse-0.7.0/src/lib/libzpool/zio_inject.c:449:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(name, spa_name(handler->zi_spa), buflen); data/zfs-fuse-0.7.0/src/zfs-fuse/fuse_listener.c:114:16: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). info.mntlen = strlen(mntpoint); data/zfs-fuse-0.7.0/src/zfs-fuse/fuse_listener.c:138:13: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). int ret = read(fd, ((char *) buf) + read_bytes, left_bytes); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:365:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int l = strlen(buf)-1; data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:405:19: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). original_len = strlen(original); data/zfs-fuse-0.7.0/src/zfs-fuse/main.c:408:41: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). snprintf(argv[1], original_len + 2, strlen(original)>1? "--%s" : "-%s", original); data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:167:9: [1] (access) umask: Ensure that umask is given most restrictive possible setting (e.g., 066 or 077) (CWE-732). umask(027); /* set newly created file permissions */ data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:327:12: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). .optlen = strlen(opt) data/zfs-fuse-0.7.0/src/zfs-fuse/util.c:344:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). sprintf(&real_opts[strlen(real_opts)],",%s",opt); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_dir.c:275:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). dl->dl_namesize = strlen(dl->dl_name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:464:18: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (!zoned || strlen(dsname) <= strlen(setpoint)) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:464:36: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (!zoned || strlen(dsname) <= strlen(setpoint)) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:590:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(parent, datasetname, parentsize); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:1766:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t orig_len = strlen(zc->zc_name); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:1778:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). p = zc->zc_name + strlen(zc->zc_name); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:1854:29: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). sizeof (zc->zc_name) - strlen(zc->zc_name), data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:1855:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). zc->zc_name + strlen(zc->zc_name), NULL, &zc->zc_cookie, NULL); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:2151:9: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(strval) + 1, strval); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:2204:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(propname) >= ZAP_MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:2208:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(valstr) >= ZAP_MAXVALUELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3122:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(uq_prefix)) == 0) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3125:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(gq_prefix)) == 0) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_ioctl.c:3611:10: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(buf, zc->zc_name, MAXPATHLEN); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:200:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(zdomain->z_domain) + 1); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:202:8: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(zdomain->z_domain) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:243:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:347:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:371:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:397:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t namesize = strlen(name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:398:20: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t linksize = strlen(link) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:431:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t snamesize = strlen(sname) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_log.c:432:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t dnamesize = strlen(dname) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:303:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). while (used + strlen(s)+1 > alloc) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:308:11: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). used += strlen(s)+1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:477:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:770:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(name && strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1091:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1166:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1355:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1453:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1536:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1617:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(name) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1619:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(newname) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_operations.c:1717:5: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if(strlen(newname) >= MAXNAMELEN) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_replay.c:159:28: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). start = (caddr_t)start + strlen(start) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_replay.c:506:17: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). link = name + strlen(name) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_replay.c:593:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). char *tname = sname + strlen(sname) + 1; data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:1382:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). ZPROP_SRC_LOCAL, 1, strlen(str) + 1, str) == 0) data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vfsops.c:1385:19: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(str, strlen(str) + 1); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:1192:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (zfsvfs->z_utf8 && u8_validate(nm, strlen(nm), data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:1271:42: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (zfsvfs->z_utf8 && u8_validate(name, strlen(name), data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:1707:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(dirname), NULL, U8_VALIDATE_ENTIRE, &error) < 0) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2062:11: [1] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant character. (void) strcpy(zap.za_name, "."); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2124:28: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). reclen = EDIRENT_RECLEN(strlen(zap.za_name)); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2126:29: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). reclen = DIRENT64_RECLEN(strlen(zap.za_name)); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2151:11: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(eodp->ed_name, zap.za_name, data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:2162:11: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(odp->d_name, zap.za_name, data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3135:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(tnm), NULL, U8_VALIDATE_ENTIRE, &error) < 0) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3382:40: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). vn_renamepath(tdvp, ZTOV(szp), tnm, strlen(tnm)); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3433:13: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int len = strlen(link); data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3445:42: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (zfsvfs->z_utf8 && u8_validate(name, strlen(name), data/zfs-fuse-0.7.0/src/zfs-fuse/zfs_vnops.c:3658:6: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). strlen(name), NULL, U8_VALIDATE_ENTIRE, &error) < 0) { data/zfs-fuse-0.7.0/src/zfs-fuse/zfsfuse_socket.c:94:2: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). strncpy(name.sun_path, ZFS_SOCK_NAME, sizeof(name.sun_path)); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:701:24: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). namebuf = kmem_zalloc(strlen(name) + 2, KM_SLEEP); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:702:9: [1] (buffer) strncpy: Easily used incorrectly; doesn't always \0-terminate or check for invalid pointers [MS-banned] (CWE-120). (void) strncpy(namebuf, name, strlen(name)); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:702:32: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). (void) strncpy(namebuf, name, strlen(name)); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:703:9: [1] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). Risk is low because the source is a constant character. (void) strcat(namebuf, "/"); data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:710:37: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strncmp(namebuf, zv->zv_name, strlen(namebuf)) == 0) data/zfs-fuse-0.7.0/src/zfs-fuse/zvol.c:713:21: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). kmem_free(namebuf, strlen(name) + 2); ANALYSIS SUMMARY: Hits = 1296 Lines analyzed = 220527 in approximately 6.17 seconds (35752 lines/second) Physical Source Lines of Code (SLOC) = 154304 Hits@level = [0] 1275 [1] 348 [2] 637 [3] 53 [4] 256 [5] 2 Hits@level+ = [0+] 2571 [1+] 1296 [2+] 948 [3+] 311 [4+] 258 [5+] 2 Hits/KSLOC@level+ = [0+] 16.6619 [1+] 8.399 [2+] 6.14372 [3+] 2.0155 [4+] 1.67202 [5+] 0.0129614 Symlinks skipped = 55 (--allowlink overrides but see doc for security issue) Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.