https://github.com/python/cpython/commit/b0842ed1ef73894dcddd248be394f945405d1099
commit: b0842ed1ef73894dcddd248be394f945405d1099
branch: 3.14
author: Stan Ulbrych <[email protected]>
committer: StanFromIreland <[email protected]>
date: 2026-07-13T07:31:44Z
summary:

[3.14] gh-148286: Fix UB in `ZstdDecompressor.unused_data` when a frame is 
decompressed in one call (GH-153258) (#153645)

(cherry picked from commit adebb68153346043c0671fa5725d269c32cc40e4)

Co-authored-by: Emma Smith <[email protected]>

files:
A Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst
M Modules/_zstd/decompressor.c

diff --git 
a/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst 
b/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst
new file mode 100644
index 000000000000000..60cd49020c954a4
--- /dev/null
+++ b/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst
@@ -0,0 +1,3 @@
+Fix undefined behavior in
+:attr:`compression.zstd.ZstdDecompressor.unused_data` when a complete frame
+was decompressed in a single call.
diff --git a/Modules/_zstd/decompressor.c b/Modules/_zstd/decompressor.c
index c9b57a898e7903f..85b67d468864890 100644
--- a/Modules/_zstd/decompressor.c
+++ b/Modules/_zstd/decompressor.c
@@ -594,9 +594,14 @@ 
_zstd_ZstdDecompressor_unused_data_get_impl(ZstdDecompressor *self)
     }
     else {
         if (self->unused_data == NULL) {
-            self->unused_data = PyBytes_FromStringAndSize(
-                                    self->input_buffer + self->in_begin,
-                                    self->in_end - self->in_begin);
+            if (self->input_buffer == NULL) {
+                self->unused_data = Py_GetConstant(Py_CONSTANT_EMPTY_BYTES);
+            }
+            else {
+                self->unused_data = PyBytes_FromStringAndSize(
+                                        self->input_buffer + self->in_begin,
+                                        self->in_end - self->in_begin);
+            }
             ret = self->unused_data;
             Py_XINCREF(ret);
         }

_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]

Reply via email to