Repository navigation
Possible overflow in typeobject.c:tail_contains #126862
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Nov 15, 2024 This one is used in
candidate = PyTuple_GET_ITEM(cur_tuple, remain[i]); for (j = 0; j < to_merge_size; j++) { PyObject *j_lst = to_merge[j]; if (tail_contains(j_lst, remain[j], candidate)) goto skip; /* continue outer loop */ }
and for the MRO resolution. Unless we have a VERY huge list of parent classes, I don't think we would hit the overflow.
- addedinterpreter-core(Objects, Python, Grammar, and Parser dirs)(Objects, Python, Grammar, and Parser dirs)pendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Nov 15, 2024 - added3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes
on Nov 15, 2024 federicovalenso commented
on Nov 15, 2024 ContributorAuthorMore actions@picnixz , should I try to overflow inheritance list? :) Or is there already protection against this?
Yes, if you can make it happen! (I don't know whether there's a protection)
For this to trigger you'd need a class with over 2**32 base classes, right? I currently have a Python terminal open where I'm trying to generate 2**32 classes to test this, and it's been running for more than half an hour already. It's probably OK to change int to Py_ssize_t here for cleanliness, but let's not add a unit test that attempts to trigger this condition.
Reacted by sobolevn, Sergey B Kirpichev, Nice Zombies and Srinivas Reddy Thatiparthy (తాటిపర్తి శ్రీనివాస్ రెడ్డి)- removedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Dec 2, 2024 - added a commit that references this issue
on Jan 10, 2025 I'll close this one as completed since we changed
inttoPy_ssize_tfor cleanliness (well,whence + 1could still overflow, but this is in the infeasible realm)
Bug report
Bug description:
whence+1 could lead to overflow for large value of whence. I think changing type from int to Py_ssize_t could fix the problem (remain is input parameter):
CPython versions tested on:
3.11
Operating systems tested on:
Linux
Linked PRs
Py_ssize_tinstead ofintwhen processing the number of super-classes #127523Py_ssize_tinstead ofintwhen processing the number of super-classes (GH-127523) #128699Py_ssize_tinstead ofintwhen processing the number of super-classes (GH-127523) #128700