From: Stan Ulbrych Date: Mon, 13 Jul 2026 07:31:44 +0000 (+0200) Subject: [3.14] gh-148286: Fix UB in `ZstdDecompressor.unused_data` when a frame is decompress... X-Git-Url: http://git.ipfire.org/index.cgi?a=commitdiff_plain;h=b0842ed1ef73894dcddd248be394f945405d1099;p=thirdparty%2FPython%2Fcpython.git [3.14] gh-148286: Fix UB in `ZstdDecompressor.unused_data` when a frame is decompressed in one call (GH-153258) (#153645) (cherry picked from commit adebb68153346043c0671fa5725d269c32cc40e4) Co-authored-by: Emma Smith --- diff --git a/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst b/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst new file mode 100644 index 000000000000..60cd49020c95 --- /dev/null +++ b/Misc/NEWS.d/next/Library/2026-07-07-13-31-52.gh-issue-148286.-qu-em.rst @@ -0,0 +1,3 @@ +Fix undefined behavior in +:attr:`compression.zstd.ZstdDecompressor.unused_data` when a complete frame +was decompressed in a single call. diff --git a/Modules/_zstd/decompressor.c b/Modules/_zstd/decompressor.c index c9b57a898e79..85b67d468864 100644 --- a/Modules/_zstd/decompressor.c +++ b/Modules/_zstd/decompressor.c @@ -594,9 +594,14 @@ _zstd_ZstdDecompressor_unused_data_get_impl(ZstdDecompressor *self) } else { if (self->unused_data == NULL) { - self->unused_data = PyBytes_FromStringAndSize( - self->input_buffer + self->in_begin, - self->in_end - self->in_begin); + if (self->input_buffer == NULL) { + self->unused_data = Py_GetConstant(Py_CONSTANT_EMPTY_BYTES); + } + else { + self->unused_data = PyBytes_FromStringAndSize( + self->input_buffer + self->in_begin, + self->in_end - self->in_begin); + } ret = self->unused_data; Py_XINCREF(ret); }