FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[3.12] gh-90949: add Expat API to prevent XML deadly allocations (CVE-2025-59375) (GH-139234) by hartwork · Pull Request #139527 · python/cpython · GitHub

/ cpython Public

[3.12] gh-90949: add Expat API to prevent XML deadly allocations (CVE-2025-59375) (GH-139234) - #139527

Merged
Yhg1s merged 9 commits into
python:3.12from
hartwork:backport-f04bea4-3.12
Dec 17, 2025
Merged

[3.12] gh-90949: add Expat API to prevent XML deadly allocations (CVE-2025-59375) (GH-139234)#139527
Yhg1s merged 9 commits into
python:3.12from
hartwork:backport-f04bea4-3.12

Conversation

hartwork commented Oct 2, 2025
edited by github-actions Bot
Loading

Copy link
Copy Markdown
Contributor

Expose the XML Expat 2.7.2 mitigation APIs to disallow use of disproportional amounts of dynamic memory from within an Expat parser (see CVE-2025-59375 for instance).

The exposed APIs are available on Expat parsers, that is, parsers created by xml.parsers.expat.ParserCreate(), as:

  • parser.SetAllocTrackerActivationThreshold(threshold), and
  • parser.SetAllocTrackerMaximumAmplification(max_factor).

(cherry picked from commit f04bea4)

CC @picnixz


📚 Documentation preview 📚: https://cpython-previews--139527.org.readthedocs.build/

picnixz and others added 4 commits October 2, 2025 23:47
CVE-2025-59375) (pythonGH-139234)

Expose the XML Expat 2.7.2 mitigation APIs to disallow use of
disproportional amounts of dynamic memory from within an Expat
parser (see CVE-2025-59375 for instance).

The exposed APIs are available on Expat parsers, that is,
parsers created by `xml.parsers.expat.ParserCreate()`, as:

- `parser.SetAllocTrackerActivationThreshold(threshold)`, and
- `parser.SetAllocTrackerMaximumAmplification(max_factor)`.
(cherry picked from commit f04bea4)

Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
…on API (python#139366)

Fix some typos left in f04bea4,
and simplify some internal functions to ease maintenance of future
mitigation APIs.

(cherry picked from commit 68a1778)

picnixz commented Oct 7, 2025

Copy link
Copy Markdown
Member

To have a good synchronization, we'll also delay 3.10 to 3.13 backports for their next release cycle (see #139359 (comment)).

picnixz self-assigned this Oct 7, 2025

ambv commented Oct 8, 2025

Copy link
Copy Markdown
Contributor

I set DO-NOT-MERGE to avoid confusion. Unset that when you think we should be releasing this.

picnixz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

The 22 additional lines are in the clinic file so all good.

picnixz requested review from Yhg1s and removed request for Yhg1s November 8, 2025 13:47

Copy link
Copy Markdown
Contributor Author

@Yhg1s do you have a minute for this? 🙏

Copy link
Copy Markdown
Contributor Author

@Yhg1s do you have a minute? 🙏

Yhg1s merged commit 0e4cd89 into python:3.12 Dec 17, 2025
30 checks passed

Copy link
Copy Markdown
Contributor Author

Thanks! 🙏

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants


Back | FazBrowse Home | New Git URL