Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Switch Statement Oddities

Introduction The grammar for the switch statement in C is simply: switch ( expression ) statement C++ inherited C’s switch and added the ability to add an optional init-statement, but that’s not central to this art…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Introduction



The grammar for the switch statement in C is simply:




        switch ( expression ) statement







C++ inherited C’s switch and added the ability to add an optional init-statement, but that’s not central to this article.




Notice what’s not there: there’s no mention of either case or default. Those are specified elsewhere in the grammar. This means the correctness of a switch statement is enforced semantically rather than syntactically. The consequences of this are that statement:




  1. Can be any statement.

  2. Is treated exactly the same as any other statement.

  3. May also contain zero or more case labels and at most one default label.






Fall-Through



One of the controversial features of C is that, within a switch statement, cases “fall through” to the next case (if any). For example, given a value of 'a' for the variable c, code such as:




switch ( c ) {
case 'a':
printf( "apple\n" );
case 'b':
printf( "banana\n" );
}






will print apple and banana because after matching 'a' and printing apple, execution simply “falls through” into the 'b' case. This is an odd result of consequence #2 above since, outside of a switch, consecutive statements naturally “fall through” from one to the next. Inside of a switch between cases, this isn’t what you want most of the time, so you can use a break (or continue if inside a loop, return, or goto).



Most compilers will allow you to request to be warned when code falls through to a next case. As of C23 or C++17, you can include the [[fallthrough]] attribute to tell the compiler that a fall-through is intentional and not to warn you:




switch ( how_good ) {
case VERY_GOOD:
printf( "very " );
[[fallthrough]];
case GOOD:
printf( "good\n" );
break;
}






Perhaps the most famous example of where fall-through is useful is Duff’s device. You can read the details of it there, but the bottom line is that code such as (rewritten in modern C):




void send( short *to, short const *from, size_t count ) {
size_t n = (count + 7) / 8;
switch ( count % 8 ) {
case 0: do { *to = *from++;
case 7: *to = *from++;
case 6: *to = *from++;
case 5: *to = *from++;
case 4: *to = *from++;
case 3: *to = *from++;
case 2: *to = *from++;
case 1: *to = *from++;
} while ( --n > 0 );
}
}






is perfectly legal as a result of consequence #3, that is the fact that the do loop is inside a switch allows any statement to have a case label.






Single Statement



With switch, the statement is invariably a compound-statement, that is a sequence of statements enclosed in {}, but it can alternatively be a single statement:




bool check_n_args( int n_args ) {
switch ( n_args ) // no { here
case 0:
case 1:
case 2:
return true;
// no } here
fprintf( stderr, "error: args must be 0-2\n" );
return false;
}






Since there is only the single statement of return true, the {} aren’t necessary just as they’d not be necessary after an if, do, else, for, or while either.



Aside from the fact that the above is an alternate way of writing:




    if ( n_args >= 0 && n_args <= 2 )
return true;






(except that the expression is evaluated only once) there’s no legitimate reason for ever using a single statement with a switch, so I’d never recommend doing it. It’s just an odd result of consequence #1 above.






default Not Last



When a switch has a default, it’s invariably last, but it can actually be anywhere within the switch:




    switch ( n_args ) {
default:
fprintf( stderr, "error: args must be 0-2\n" );
return false;
case 0:
// ...






In terms of performance, the position of default (or indeed the order of the cases) doesn’t matter. The only technical reason for not having default last would be if you wanted to have execution fall-through into the next case. Any other reason would be purely stylistic, e.g., you want to handle the common case first followed by special cases.






Statements Before the First Case



It’s also possible to have statements before the first case, for example:




switch ( n_args ) {
printf( "never executed\n" );
case 0:
// ...






Such statements are never executed. Most compilers will warn about this. As far as I know, there’s no reason for ever having statements before the first case.



However, it’s marginally useful to have declarations before the first case, for example:




switch ( n_args ) {
int i;
case 0:
i = f();
// ...
break;
case 1:
i = g();
// ...
break;
}






This is marginally useful when a variable is used only within the scope of the switch by one or more cases. Note that you should not initialize such variables like:




switch ( n_args ) {
int i = 0; // WRONG: do _not_ initialize!
// ...






because, even though the variable is declared, its initialization code is never executed (just like the printf() in a previous example is never executed), so the code is deceptive. Instead, you must initialize such variables in each case that uses them.



Even though simple declarations (without initialization) are not executable code, some compilers will still (erroneously, IMHO) warn about them. Therefore, such declarations are not useful.



If you really want declarations only within the scope of a switch, you can either put them in the first case or only in the case(s) that use them. However, prior to C23, declarations immediately after a label are not allowed:




switch ( n_args ) {
case 0:
int i; // error (pre-C23)
// ...






To work around that restriction, you can add {} for a case:




    case 0: {
int i; // OK now (all C versions)
// ...
}









A break-able Block



If you have a long block of code that you want to jump to the end of, there are a few ways to do it:




  1. A sequence of if-else statements; or;

  2. A sequence of if-goto statements; or;

  3. A do { ... } while (0) statement with breaks.



Each has its trade-offs. Another way would be:




#define BLOCK  switch (0) default:

void f() {
BLOCK {
// ...
if ( condition_1 )
break;
// ... lots more code ...
}

// "break" above jumps here






Hence, it’s most similar to do { ... } while (0), but without having to put the while (0) at the end.






Conclusion



The apparent simplicity of the switch statement in C (and C++) is deceptive in that it allows several odd ways to write code using them, some useful, some not. The most useful is Duff’s device for loop unrolling.

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - Switch Statement Oddities
id: c6f81cbe-8f1d-43e9-8b79-74c27d1e7643
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-26
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-26"
        description = "YARA Signature for "
    strings:
        $str = "Switch Statement Oddities" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Switch Statement Oddities")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Switch Statement Oddities*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Switch Statement Oddities"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Switch Statement Oddities.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Switch Statement Oddities

Thematisch verwandte Begriffe: Switch, Statement, Oddities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-88003 | InvoicePlane is a self-hosted open source application for managing invoi…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag