https://github.com/python/cpython/commit/3a27a352f45d42543ebe3074626a67c61563d546
commit: 3a27a352f45d42543ebe3074626a67c61563d546
branch: 3.14
author: Miss Islington (bot) <[email protected]>
committer: vstinner <[email protected]>
date: 2026-09-07T19:59:49Z
summary:
[3.14] gh-156939: Fix struct.pack('0p', bytes) (GH-157071) (#157130)
gh-156939: Fix struct.pack('0p', bytes) (GH-157071)
If the Pascal string is empty (size=0), do not write the size prefix.
Previously, a NUL byte was written outsize the buffer (buffer
overflow). In practice, the write remains into allocated memory
and is silently ignored: no memory is corrupted.
(cherry picked from commit 23525c90f539f621c802f2725e91ff234a69e1e0)
Co-authored-by: Victor Stinner <[email protected]>
files:
M Modules/_struct.c
diff --git a/Modules/_struct.c b/Modules/_struct.c
index 614512fe35f047..788dd39164f68c 100644
--- a/Modules/_struct.c
+++ b/Modules/_struct.c
@@ -2231,7 +2231,9 @@ s_pack_internal(PyStructObject *soself, PyObject *const
*args, int offset,
memcpy(res + 1, p, n);
if (n > 255)
n = 255;
- *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+ if (n > 0) {
+ *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+ }
} else {
if (e->pack(state, res, v, e) < 0) {
if (PyLong_Check(v) &&
PyErr_ExceptionMatches(PyExc_OverflowError))
_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]