Skip to content

[3.15] gh-153578: Fix out-of-bounds write in bytearray.extend() with a reentrant __buffer__ (GH-153579) - #156007

Open
miss-islington wants to merge 1 commit into
python:3.15from
miss-islington:backport-e675e37-3.15
Open

[3.15] gh-153578: Fix out-of-bounds write in bytearray.extend() with a reentrant __buffer__ (GH-153579)#156007
miss-islington wants to merge 1 commit into
python:3.15from
miss-islington:backport-e675e37-3.15

Conversation

@miss-islington

@miss-islington miss-islington commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

bytearray.extend() clamped only the high bound of the append range to the
current size after acquiring the argument's buffer, so a buffer that shrinks
the bytearray left the low bound past the high bound and ran a negative-size
memmove. Clamp the low bound too, matching bytearray.iadd.
(cherry picked from commit e675e37)

Co-authored-by: tonghuaroot (童话) tonghuaroot@gmail.com

… reentrant __buffer__ (pythonGH-153579)

bytearray.extend() clamped only the high bound of the append range to the
current size after acquiring the argument's buffer, so a __buffer__ that shrinks
the bytearray left the low bound past the high bound and ran a negative-size
memmove. Clamp the low bound too, matching bytearray.__iadd__.
(cherry picked from commit e675e37421357cf0319c5bca2cec533f0909d5b8)

Co-authored-by: tonghuaroot (童话) <tonghuaroot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants