Skip to content

Incorrect use of the C API in getpath_joinpath() #97758

Description

@serhiy-storchaka

If the getpath.joinpath() is called without arguments, it tries to return an empty string and calls PyUnicode_FromString(NULL) for this, which causes a crash. The correct way of creating an empty string is PyUnicode_FromStringAndSize(NULL, 0), or PyUnicode_FromString(""), or PyUnicode_FromStringAndSize("", 0).

Alternatively, the function could raise a TypeError instead of returning an empty string.

@zooba @vstinner

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    type-crashA hard crash of the interpreter, possibly with a core dump
    on Oct 3, 2022
  2. added 2 commits that reference this issue on Oct 3, 2022
  3. added a commit that references this issue on Oct 5, 2022
  4. added a commit that references this issue on Oct 5, 2022
  5. added a commit that references this issue on Oct 6, 2022
  6. added a commit that references this issue on Oct 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.11only security fixes3.12only security fixestype-bugAn unexpected behavior, bug, or errortype-crashA hard crash of the interpreter, possibly with a core dump

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions