https://github.com/python/cpython/commit/5d1f8ae23a81d9a397e70f959b713ba2c5a5d8f1 commit: 5d1f8ae23a81d9a397e70f959b713ba2c5a5d8f1 branch: 3.14 author: Miss Islington (bot) <[email protected]> committer: vstinner <[email protected]> date: 2026-09-14T16:12:28+02:00 summary:
[3.14] gh-156939: Fix xmlcharrefreplace() buffer overflow (GH-157109) (#157233) * gh-156939: Fix xmlcharrefreplace() buffer overflow (GH-157109) Write into a temporary buffer to not write the trailing NUL byte into the writer. Previously, the NUL byte was written outsize the writer buffer. (cherry picked from commit 939865532c00e25842209f56953abe0361ab22a1) Co-authored-by: Victor Stinner <[email protected]> * Replace _Py_MAX_UNICODE with MAX_UNICODE --------- Co-authored-by: Victor Stinner <[email protected]> files: M Objects/unicodeobject.c diff --git a/Objects/unicodeobject.c b/Objects/unicodeobject.c index 6bd9e7d607cc414..735cc04734e4778 100644 --- a/Objects/unicodeobject.c +++ b/Objects/unicodeobject.c @@ -961,10 +961,16 @@ xmlcharrefreplace(_PyBytesWriter *writer, char *str, /* generate replacement */ for (i = collstart; i < collend; ++i) { - size = sprintf(str, "&#%d;", PyUnicode_READ(kind, data, i)); - if (size < 0) { - return NULL; - } + // Use snprintf() with a temporary buffer to not write the trailing + // NUL byte in the writer buffer. + Py_BUILD_ASSERT(MAX_UNICODE <= 0x10ffff); + // len('\0') is 11 bytes. + char buffer[11]; + Py_UCS4 ch = PyUnicode_READ(kind, data, i); + size = snprintf(buffer, sizeof(buffer), "&#%d;", ch); + assert(4 <= size && (size_t)size <= (sizeof(buffer) - 1)); + + memcpy(str, buffer, size); str += size; } return str; _______________________________________________ Python-checkins mailing list -- [email protected] To unsubscribe send an email to [email protected] https://mail.python.org/mailman3//lists/python-checkins.python.org Member address: [email protected]
