https://github.com/python/cpython/commit/a47148386bd2afe3f703208107cc4988913030c8 commit: a47148386bd2afe3f703208107cc4988913030c8 branch: 3.13 author: Miss Islington (bot) <[email protected]> committer: vstinner <[email protected]> date: 2026-09-15T15:01:25Z summary:
[3.13] gh-156939: Fix xmlcharrefreplace() buffer overflow (GH-157109) (#157234) * gh-156939: Fix xmlcharrefreplace() buffer overflow (GH-157109) Write into a temporary buffer to not write the trailing NUL byte into the writer. Previously, the NUL byte was written outsize the writer buffer. (cherry picked from commit 939865532c00e25842209f56953abe0361ab22a1) Co-authored-by: Victor Stinner <[email protected]> * Replace _Py_MAX_UNICODE with MAX_UNICODE --------- Co-authored-by: Victor Stinner <[email protected]> files: M Objects/unicodeobject.c diff --git a/Objects/unicodeobject.c b/Objects/unicodeobject.c index 4c987fa7dbc356..60cd9441462ea1 100644 --- a/Objects/unicodeobject.c +++ b/Objects/unicodeobject.c @@ -938,10 +938,16 @@ xmlcharrefreplace(_PyBytesWriter *writer, char *str, /* generate replacement */ for (i = collstart; i < collend; ++i) { - size = sprintf(str, "&#%d;", PyUnicode_READ(kind, data, i)); - if (size < 0) { - return NULL; - } + // Use snprintf() with a temporary buffer to not write the trailing + // NUL byte in the writer buffer. + Py_BUILD_ASSERT(MAX_UNICODE <= 0x10ffff); + // len('\0') is 11 bytes. + char buffer[11]; + Py_UCS4 ch = PyUnicode_READ(kind, data, i); + size = snprintf(buffer, sizeof(buffer), "&#%d;", ch); + assert(4 <= size && (size_t)size <= (sizeof(buffer) - 1)); + + memcpy(str, buffer, size); str += size; } return str; _______________________________________________ Python-checkins mailing list -- [email protected] To unsubscribe send an email to [email protected] https://mail.python.org/mailman3//lists/python-checkins.python.org Member address: [email protected]
