https://github.com/python/cpython/commit/23525c90f539f621c802f2725e91ff234a69e1e0
commit: 23525c90f539f621c802f2725e91ff234a69e1e0
branch: main
author: Victor Stinner <[email protected]>
committer: vstinner <[email protected]>
date: 2026-09-07T21:32:25+02:00
summary:
gh-156939: Fix struct.pack('0p', bytes) (#157071)
If the Pascal string is empty (size=0), do not write the size prefix.
Previously, a NUL byte was written outsize the buffer (buffer
overflow). In practice, the write remains into allocated memory
and is silently ignored: no memory is corrupted.
files:
M Modules/_struct.c
diff --git a/Modules/_struct.c b/Modules/_struct.c
index 352312fb0b4c19..8caadf091767e3 100644
--- a/Modules/_struct.c
+++ b/Modules/_struct.c
@@ -2424,7 +2424,9 @@ s_pack_internal(PyStructObject *soself, PyObject *const
*args,
memcpy(res + 1, p, n);
if (n > 255)
n = 255;
- *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+ if (n > 0) {
+ *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
+ }
} else {
if (e->pack(state, res, v, e) < 0) {
if (PyLong_Check(v) &&
PyErr_ExceptionMatches(PyExc_OverflowError))
_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]