Skip to content

Some object-to-AST conversions are missing error checks #105588

Description

@brandtbucher

The generated code in Python-ast.c is missing error checks following the construction of C-level alias, arg, comprehension, keyword, match_item, and withitem nodes from their Python object counterparts. This means it's possible to crash the interpreter by attempting to compile an AST where a required member of these nodes is replaced with None:

>>> import ast
>>> tree = ast.parse("""
... match ...:
...     case THIS:
...         ...
... """)
>>> tree.body[0].cases[0].pattern = None
>>> compile(tree, "<crash>", "exec")
Segmentation fault

I'll have a PR up in a minute with the one-line fix.

Linked PRs

Activity

  1. added
    interpreter-core(Objects, Python, Grammar, and Parser dirs)
    3.11only security fixes
    type-crashA hard crash of the interpreter, possibly with a core dump
    3.12only security fixes
    triagedThe issue has been accepted as valid by a triager.
    3.13only security fixes
    on Jun 9, 2023
  2. self-assigned this
    on Jun 9, 2023
  3. added a commit that references this issue on Jun 15, 2023
  4. added 2 commits that reference this issue on Jun 15, 2023
  5. added 2 commits that reference this issue on Jun 15, 2023
  6. added a commit that references this issue on Jun 16, 2023
  7. added a commit that references this issue on Jun 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

3.11only security fixes3.12only security fixes3.13only security fixesinterpreter-core(Objects, Python, Grammar, and Parser dirs)triagedThe issue has been accepted as valid by a triager.type-crashA hard crash of the interpreter, possibly with a core dump

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions