FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

gh-101659: initialize stack variable _sharedexception by gaogaotiantian · Pull Request #103048 · python/cpython · GitHub

/ cpython Public

gh-101659: initialize stack variable _sharedexception - #103048

Closed
gaogaotiantian wants to merge 1 commit into
python:mainfrom
gaogaotiantian:uninitialized-sharedexception
Closed

gh-101659: initialize stack variable _sharedexception#103048
gaogaotiantian wants to merge 1 commit into
python:mainfrom
gaogaotiantian:uninitialized-sharedexception

Conversation

gaogaotiantian commented Mar 26, 2023
edited by bedevere-bot
Loading

Copy link
Copy Markdown
Member

In ./Modules/_xxsubinterpretersmodule.c a variable _sharedexception exc on stack is declared introduced in #102659. The variable is not initialized.

In _run_script, it's possible that the function hits an error and goes to error label without properly initializing the variable. Then _sharedexception_bind can also potentially error out to trigger _sharedexception_clear(sharedexc), which may free the uninitialized pointer. I have not found an exploit on this, but there's a potential path. Also the fix is so easy and cheap so I think we can just initialize the variable with no_exception (basically {0}).

Oh BTW, gcc complains with the possible unitialized variable.

I would guess @ericsnowcurrently is the right person to review this? Thanks!

Copy link
Copy Markdown
Member

CC @ericsnowcurrently

arhadthedev added type-bug An unexpected behavior, bug, or error extension-modules C modules in the Modules dir topic-subinterpreters labels Mar 30, 2023

Copy link
Copy Markdown
Member Author

Fixed in #103245

gaogaotiantian deleted the uninitialized-sharedexception branch April 9, 2023 03:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting review extension-modules C modules in the Modules dir topic-subinterpreters type-bug An unexpected behavior, bug, or error

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants


Back | FazBrowse Home | New Git URL