Skip to content

Commit 1c5df82

Browse files
[3.13] gh-156939: Fix struct.pack('0p', bytes) (GH-157071) (#157131)
gh-156939: Fix struct.pack('0p', bytes) (GH-157071) If the Pascal string is empty (size=0), do not write the size prefix. Previously, a NUL byte was written outsize the buffer (buffer overflow). In practice, the write remains into allocated memory and is silently ignored: no memory is corrupted. (cherry picked from commit 23525c9) Co-authored-by: Victor Stinner <vstinner@python.org>
1 parent 88f6017 commit 1c5df82

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

‎Modules/_struct.c‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2020,7 +2020,9 @@ s_pack_internal(PyStructObject *soself, PyObject *const *args, int offset,
20202020
memcpy(res + 1, p, n);
20212021
if (n > 255)
20222022
n = 255;
2023-
*res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
2023+
if (n > 0) {
2024+
*res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char);
2025+
}
20242026
} else {
20252027
if (e->pack(state, res, v, e) < 0) {
20262028
if (PyLong_Check(v) && PyErr_ExceptionMatches(PyExc_OverflowError))

0 commit comments

Comments
 (0)