]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
[3.14] gh-144759: Fix undefined behavior from NULL pointer arithmetic in lexer (GH...
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Sun, 15 Feb 2026 15:10:15 +0000 (16:10 +0100)
committerGitHub <noreply@github.com>
Sun, 15 Feb 2026 15:10:15 +0000 (15:10 +0000)
commit70ecd561135b31a8ece6f9d459b91734ab51db25
treee7fff2f3cf9467381476ca8aa18cda788eeb1d2e
parent5b0c1f780f25bf8b4dcf687a20658ad63cb99140
[3.14] gh-144759: Fix undefined behavior from NULL pointer arithmetic in lexer (GH-144788) (#144834)

gh-144759: Fix undefined behavior from NULL pointer arithmetic in lexer (GH-144788)

Guard against NULL pointer arithmetic in `_PyLexer_remember_fstring_buffers`
and `_PyLexer_restore_fstring_buffers`. When `start` or `multi_line_start`
are NULL (uninitialized in tok_mode_stack[0]), performing `NULL - tok->buf`
is undefined behavior. Add explicit NULL checks to store -1 as sentinel
and restore NULL accordingly.

Add test_lexer_buffer_realloc_with_null_start to test_repl.py that
exercises the code path where the lexer buffer is reallocated while
tok_mode_stack[0] has NULL start/multi_line_start pointers. This
triggers _PyLexer_remember_fstring_buffers and verifies the NULL
checks prevent undefined behavior.
(cherry picked from commit e6110efd03259acd1895cff63fbfa115ac5f16dc)

Co-authored-by: Ramin Farajpour Cami <ramin.blackhat@gmail.com>
Lib/test/test_repl.py
Misc/NEWS.d/next/Core_and_Builtins/2026-02-13-12-00-00.gh-issue-144759.d3qYpe.rst [new file with mode: 0644]
Parser/lexer/buffer.c