]> git.ipfire.org Git - thirdparty/Python/cpython.git/commitdiff
[3.14] gh-152682: Fix NULL dereference on OOM in `symtable_visit_type_param_bound_or_...
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Mon, 6 Jul 2026 16:35:58 +0000 (18:35 +0200)
committerGitHub <noreply@github.com>
Mon, 6 Jul 2026 16:35:58 +0000 (17:35 +0100)
In `symtable_visit_type_param_bound_or_default()`, when a reserved name
(e.g. `__classdict__`) is used as a type parameter, `PyUnicode_FromFormat()`
is called to build the SyntaxError message. If the allocation fails and
returns NULL, the subsequent `PyErr_SetObject()` and `Py_DECREF()` calls
would dereference NULL, causing a segfault.

Fix by returning 0 immediately when `PyUnicode_FromFormat()` returns NULL.
This propagates the MemoryError set by `PyUnicode_FromFormat()`.

The bug was introduced in gh-128632 (commit 891c61c).
(cherry picked from commit 10ed03edf128ed1101ab8d04bcd715f2033fec55)

Co-authored-by: Petr Vaganov <petrvaganoff@gmail.com>
* Remove test

---------

Co-authored-by: Petr Vaganov <petrvaganoff@gmail.com>
Co-authored-by: Stan Ulbrych <stan@python.org>
Misc/NEWS.d/next/Core_and_Builtins/2026-06-30-14-00-00.gh-issue-152682.yId7e5.rst [new file with mode: 0644]
Python/symtable.c

diff --git a/Misc/NEWS.d/next/Core_and_Builtins/2026-06-30-14-00-00.gh-issue-152682.yId7e5.rst b/Misc/NEWS.d/next/Core_and_Builtins/2026-06-30-14-00-00.gh-issue-152682.yId7e5.rst
new file mode 100644 (file)
index 0000000..aba0b59
--- /dev/null
@@ -0,0 +1,3 @@
+Fix NULL pointer dereference in :func:`compile` when a reserved name (e.g.
+``__classdict__``) is used as a type parameter name and memory allocation
+fails while formatting the error message.
index 7525df2727aaf09ae802ee659cd597e2d56b8d3d..6847f97cf476e977adb458c24b0ca8a2213f8b64 100644 (file)
@@ -2608,6 +2608,9 @@ symtable_visit_type_param_bound_or_default(
 
         PyObject *error_msg = PyUnicode_FromFormat("reserved name '%U' cannot be "
                                                    "used for type parameter", name);
+        if (error_msg == NULL) {
+            return 0;
+        }
         PyErr_SetObject(PyExc_SyntaxError, error_msg);
         Py_DECREF(error_msg);
         SET_ERROR_LOCATION(st->st_filename, LOCATION(tp));