Skip to content

[3.14] gh-153578: Fix out-of-bounds write in bytearray.extend() with a reentrant __buffer__ (GH-153579) - #156008

Merged
serhiy-storchaka merged 1 commit into
python:3.14from
miss-islington:backport-e675e37-3.14
Aug 18, 2026
Merged

[3.14] gh-153578: Fix out-of-bounds write in bytearray.extend() with a reentrant __buffer__ (GH-153579)#156008
serhiy-storchaka merged 1 commit into
python:3.14from
miss-islington:backport-e675e37-3.14

Conversation

@miss-islington

@miss-islington miss-islington commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

bytearray.extend() clamped only the high bound of the append range to the
current size after acquiring the argument's buffer, so a buffer that shrinks
the bytearray left the low bound past the high bound and ran a negative-size
memmove. Clamp the low bound too, matching bytearray.iadd.
(cherry picked from commit e675e37)

Co-authored-by: tonghuaroot (童话) tonghuaroot@gmail.com

… reentrant __buffer__ (pythonGH-153579)

bytearray.extend() clamped only the high bound of the append range to the
current size after acquiring the argument's buffer, so a __buffer__ that shrinks
the bytearray left the low bound past the high bound and ran a negative-size
memmove. Clamp the low bound too, matching bytearray.__iadd__.
(cherry picked from commit e675e37421357cf0319c5bca2cec533f0909d5b8)

Co-authored-by: tonghuaroot (童话) <tonghuaroot@gmail.com>
@serhiy-storchaka
serhiy-storchaka enabled auto-merge (squash) August 18, 2026 12:33
@serhiy-storchaka
serhiy-storchaka merged commit 1e66eae into python:3.14 Aug 18, 2026
51 checks passed
@miss-islington
miss-islington deleted the backport-e675e37-3.14 branch August 18, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants