I can reproduce with 2.3, but not 2.4. This was fixed in https://trac.cppcheck.net/ticket/10186.
This is now fixed on the development branch of cppcheck and will be part of next release. For the first example, all three memory leaks will be reported and for the second, all five leaks will be reported, with the correct lines. Thanks for reporting!
This false positive is fixed in the git repo and will be part of the next release. There is still room for improvements to set the correct values but t least wrong values will not be set.
The server has a limit of 1Mb for info messages (2Mb for results), so for large packages, these are rejected. I thought that message was confusing too when I first saw it, so perhaps we could improve it somehow?
I tested your example and from cppcheck 1.87 and forward, there is no warning.
Thanks , this is fixed now.
Sorry for the late answer. Currently it is not possible to get the warning with memcpy. It was removed in 1.88 (https://github.com/danmar/cppcheck/commit/2ecfae0a9849d94b577942b2601835e4b309c2cc). The commit message says it didn't work well, but I don't know what didn't work well. As far as I could see, there has never been warnings for memset
That worked, thanks.