Repository navigation
ctypes: Crash if manually-created CField instance is used #78878
Description
Activity
It is possible to manually create an instance of private CField type which is used by ctypes to represent fields of Structure and Union types. This instance will be uninitialized because it's normally initialized when instances of Structure/Union are created, so calling its methods may crash the interpreter:
from ctypes import * class S(Structure): _fields_ = [('x', c_int)] CField = type(S.x) f = CField() repr(f) # Crash here
Is this issue worth fixing?
If so, is the correct way to set tp_new slot to NULL and fix the internal callers so that users wouldn't be able to create CField instances?
- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of lifetype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Sep 15, 2018 Is this issue worth fixing?
Definitely yes.
If so, is the correct way to set tp_new slot to NULL and fix the internal callers so that users wouldn't be able to create CField instances?
I think yes.
Do you mind to create a PR?
I have try to cancel this PyCField_new function, but i am not sure I haven't break the code structure.
ping
- added3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixesand removed3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life
on Jan 23, 2022 - added a commit that references this issue
on Dec 21, 2022 - added a commit that references this issue
on Dec 28, 2022
_ctypes.CField#14837Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs
_ctypes.CField(GH-14837) #100413