Skip to content

ctypes: Crash if manually-created CField instance is used #78878

Description

@izbyshev
mannequin
BPO 34697
Nosy @amauryfa, @abalkin, @meadori, @berkerpeksag, @serhiy-storchaka, @izbyshev, @tirkarthi, @shihai1991
PRs
  • gh-78878: Fix crash when creating an instance of _ctypes.CField #14837
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2018-09-15.17:13:13.204>
    labels = ['3.10', 'ctypes', '3.9', 'type-crash', '3.11']
    title = 'ctypes: Crash if manually-created CField instance is used'
    updated_at = <Date 2022-01-23.19:52:13.578>
    user = 'https://github.com/izbyshev'

    bugs.python.org fields:

    activity = <Date 2022-01-23.19:52:13.578>
    actor = 'iritkatriel'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['ctypes']
    creation = <Date 2018-09-15.17:13:13.204>
    creator = 'izbyshev'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 34697
    keywords = ['patch']
    message_count = 4.0
    messages = ['325448', '347814', '348113', '348944']
    nosy_count = 8.0
    nosy_names = ['amaury.forgeotdarc', 'belopolsky', 'meador.inge', 'berker.peksag', 'serhiy.storchaka', 'izbyshev', 'xtreak', 'shihai1991']
    pr_nums = ['14837']
    priority = 'normal'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'crash'
    url = 'https://bugs.python.org/issue34697'
    versions = ['Python 3.9', 'Python 3.10', 'Python 3.11']

    Linked PRs

    Activity

    1. izbyshev commented on Sep 15, 2018

      izbyshevmannequin
      MannequinAuthor

      It is possible to manually create an instance of private CField type which is used by ctypes to represent fields of Structure and Union types. This instance will be uninitialized because it's normally initialized when instances of Structure/Union are created, so calling its methods may crash the interpreter:

      from ctypes import *
      
      class S(Structure):
          _fields_ = [('x', c_int)]
      
      CField = type(S.x)
      f = CField()
      repr(f) # Crash here

      Is this issue worth fixing?

      If so, is the correct way to set tp_new slot to NULL and fix the internal callers so that users wouldn't be able to create CField instances?

    2. serhiy-storchaka commented on Jul 13, 2019

      @serhiy-storchaka
      Member

      Is this issue worth fixing?

      Definitely yes.

      If so, is the correct way to set tp_new slot to NULL and fix the internal callers so that users wouldn't be able to create CField instances?

      I think yes.

      Do you mind to create a PR?

    3. shihai1991 commented on Jul 18, 2019

      @shihai1991
      Member

      I have try to cancel this PyCField_new function, but i am not sure I haven't break the code structure.

    4. shihai1991 commented on Aug 3, 2019

      @shihai1991
      Member

      ping

    5. transferred this issue fromon Apr 10, 2022
    6. added a commit that references this issue on Dec 21, 2022
    7. added 2 commits that reference this issue on Dec 21, 2022
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      3.10 (EOL)end of life3.11only security fixes3.9 (EOL)end of lifetopic-ctypestype-crashA hard crash of the interpreter, possibly with a core dump

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions