https://github.com/python/cpython/commit/3a27a352f45d42543ebe3074626a67c61563d546
commit: 3a27a352f45d42543ebe3074626a67c61563d546
branch: 3.14
author: Miss Islington (bot) <[email protected]>
committer: vstinner <[email protected]>
date: 2026-09-07T19:59:49Z
summary:

[3.14] gh-156939: Fix struct.pack('0p', bytes) (GH-157071) (#157130)

gh-156939: Fix struct.pack('0p', bytes) (GH-157071)

If the Pascal string is empty (size=0), do not write the size prefix.
Previously, a NUL byte was written outsize the buffer (buffer
overflow). In practice, the write remains into allocated memory
and is silently ignored: no memory is corrupted.
(cherry picked from commit 23525c90f539f621c802f2725e91ff234a69e1e0)

Co-authored-by: Victor Stinner <[email protected]>

files:
M Modules/_struct.c

diff --git a/Modules/_struct.c b/Modules/_struct.c
index 614512fe35f047..788dd39164f68c 100644
--- a/Modules/_struct.c
+++ b/Modules/_struct.c
@@ -2231,7 +2231,9 @@ s_pack_internal(PyStructObject *soself, PyObject *const 
*args, int offset,
                     memcpy(res + 1, p, n);
                 if (n > 255)
                     n = 255;
-                *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+                if (n > 0) {
+                    *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+                }
             } else {
                 if (e->pack(state, res, v, e) < 0) {
                     if (PyLong_Check(v) && 
PyErr_ExceptionMatches(PyExc_OverflowError))

_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]

Reply via email to