Skip to content

Possible overflow in typeobject.c:tail_contains #126862

Description

@federicovalenso

Bug report

Bug description:

whence+1 could lead to overflow for large value of whence. I think changing type from int to Py_ssize_t could fix the problem (remain is input parameter):

static int
pmerge(PyObject *acc, PyObject **to_merge, Py_ssize_t to_merge_size)
{
...
    remain = PyMem_New(Py_ssize_t, to_merge_size);

CPython versions tested on:

3.11

Operating systems tested on:

Linux

Linked PRs

Activity

  1. picnixz commented on Nov 15, 2024

    @picnixz
    Member

    This one is used in

            candidate = PyTuple_GET_ITEM(cur_tuple, remain[i]);
            for (j = 0; j < to_merge_size; j++) {
                PyObject *j_lst = to_merge[j];
                if (tail_contains(j_lst, remain[j], candidate))
                    goto skip; /* continue outer loop */
            }

    and for the MRO resolution. Unless we have a VERY huge list of parent classes, I don't think we would hit the overflow.

  2. added
    interpreter-core(Objects, Python, Grammar, and Parser dirs)
    pendingThe issue will be closed if no feedback is provided
    on Nov 15, 2024
  3. picnixz commented on Nov 15, 2024

    @picnixz
    Member
  4. added
    3.12only security fixes
    3.13only security fixes
    3.14bugs and security fixes
    on Nov 15, 2024
  5. federicovalenso commented on Nov 15, 2024

    @federicovalenso
    ContributorAuthor

    @picnixz , should I try to overflow inheritance list? :) Or is there already protection against this?

  6. picnixz commented on Nov 15, 2024

    @picnixz
    Member

    Yes, if you can make it happen! (I don't know whether there's a protection)

  7. JelleZijlstra commented on Nov 15, 2024

    @JelleZijlstra
    Member

    For this to trigger you'd need a class with over 2**32 base classes, right? I currently have a Python terminal open where I'm trying to generate 2**32 classes to test this, and it's been running for more than half an hour already. It's probably OK to change int to Py_ssize_t here for cleanliness, but let's not add a unit test that attempts to trigger this condition.

  8. removed
    pendingThe issue will be closed if no feedback is provided
    on Dec 2, 2024
  9. added a commit that references this issue on Jan 10, 2025
  10. added 2 commits that reference this issue on Jan 10, 2025
  11. added 2 commits that reference this issue on Jan 10, 2025
  12. picnixz commented on Jan 11, 2025

    @picnixz
    Member

    I'll close this one as completed since we changed int to Py_ssize_t for cleanliness (well, whence + 1 could still overflow, but this is in the infeasible realm)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.12only security fixes3.13only security fixes3.14bugs and security fixesinterpreter-core(Objects, Python, Grammar, and Parser dirs)type-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions