gh-120298: Fix use-after-free in `list_richcompare_impl` (GH-120303)
(cherry picked from commit
141babad9b4eceb83371bf19ba3a36b50dd05250)
Co-authored-by: Nikita Sobolev <mail@sobolevn.me>
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
list4 = [1]
self.assertFalse(list3 == list4)
+ def test_lt_operator_modifying_operand(self):
+ # See gh-120298
+ class evil:
+ def __lt__(self, other):
+ other.clear()
+ return NotImplemented
+
+ a = [[evil()]]
+ with self.assertRaises(TypeError):
+ a[0] < a
+
@cpython_only
def test_preallocation(self):
iterable = [0] * 10
--- /dev/null
+Fix use-after free in ``list_richcompare_impl`` which can be invoked via
+some specificly tailored evil input.
}
/* Compare the final item again using the proper operator */
- return PyObject_RichCompare(vl->ob_item[i], wl->ob_item[i], op);
+ PyObject *vitem = vl->ob_item[i];
+ PyObject *witem = wl->ob_item[i];
+ Py_INCREF(vitem);
+ Py_INCREF(witem);
+ PyObject *result = PyObject_RichCompare(vl->ob_item[i], wl->ob_item[i], op);
+ Py_DECREF(vitem);
+ Py_DECREF(witem);
+ return result;
}
static PyObject *