From: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com> Date: Tue, 14 Jul 2026 16:52:23 +0000 (+0200) Subject: [3.15] gh-151912: Fix segfault in `type()` with NULL `tp_new` metaclasses (GH-151916... X-Git-Tag: v3.15.0b4~24 X-Git-Url: http://git.ipfire.org/index.cgi?a=commitdiff_plain;h=edbc1fe09f046ccbe885051d93cf65d253ba0867;p=thirdparty%2FPython%2Fcpython.git [3.15] gh-151912: Fix segfault in `type()` with NULL `tp_new` metaclasses (GH-151916) (#153707) gh-151912: Fix segfault in `type()` with NULL `tp_new` metaclasses (GH-151916) (cherry picked from commit f160f16373f9ea3f636bc5cd6fb4be7e150bb27f) Co-authored-by: Santhosh .I 🦇 --- diff --git a/Lib/test/test_descr.py b/Lib/test/test_descr.py index 8a8e70214e27..ba504119d294 100644 --- a/Lib/test/test_descr.py +++ b/Lib/test/test_descr.py @@ -815,6 +815,15 @@ class ClassPropertiesAndMethods(unittest.TestCase): class X(int(), C): pass + @unittest.skipIf(_testcapi is None, 'need the _testcapi module') + def test_type_with_null_new_metaclass(self): + metaclass = _testcapi.HeapCTypeMetaclassNullNew + base = _testcapi.pytype_fromspec_meta(metaclass) + + # Exercise type_new's metaclass selection path, not a direct call. + with self.assertRaisesRegex(TypeError, r"cannot create '.*' instances"): + type("Derived", (base,), {}) + def test_module_subclasses(self): # Testing Python subclass of module... log = [] diff --git a/Misc/NEWS.d/next/Core_and_Builtins/2026-06-22-14-48-22.gh-issue-151912.YcxfnU.rst b/Misc/NEWS.d/next/Core_and_Builtins/2026-06-22-14-48-22.gh-issue-151912.YcxfnU.rst new file mode 100644 index 000000000000..07b73949b438 --- /dev/null +++ b/Misc/NEWS.d/next/Core_and_Builtins/2026-06-22-14-48-22.gh-issue-151912.YcxfnU.rst @@ -0,0 +1 @@ +Fixed a crash in ``type()`` when selecting a metaclass whose ``tp_new`` slot is ``NULL``. Such metaclasses are now rejected with ``TypeError`` instead of causing a NULL pointer dereference. diff --git a/Objects/typeobject.c b/Objects/typeobject.c index 969ae450013a..f763f9f5eba5 100644 --- a/Objects/typeobject.c +++ b/Objects/typeobject.c @@ -5026,6 +5026,13 @@ type_new_get_bases(type_new_ctx *ctx, PyObject **type) if (winner != ctx->metatype) { if (winner->tp_new != type_new) { + /* Check if tp_new is NULL (cannot instantiate this type) */ + if (winner->tp_new == NULL) { + PyErr_Format(PyExc_TypeError, + "cannot create '%.400s' instances", + winner->tp_name); + return -1; + } /* Pass it to the winner */ *type = winner->tp_new(winner, ctx->args, ctx->kwds); if (*type == NULL) {