Skip to content

Out of bounds in traceback.c when alloca() is used over VLA #145792

Description

@fuhsnn

Bug report

Bug description:

#if defined(__STDC_NO_VLA__) && (__STDC_NO_VLA__ == 1)
/* Use alloca() for VLAs. */
# define VLA(type, name, size) type *name = alloca(size)
#elif !defined(__STDC_NO_VLA__) || (__STDC_NO_VLA__ == 0)
/* Use actual C VLAs.*/
# define VLA(type, name, size) type name[size]
#elif defined(CAN_C_BACKTRACE)

For the same size, VLA type[size] will allocate (sizeof(type) * size) but alloca(size) will only allocate (1 * size), which is significantly smaller than intended and will cause subsequent accesses of the allocation to be out of bounds, potentially corrupting the stack.

CPython versions tested on:

3.14

Operating systems tested on:

Linux

Linked PRs

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    on Mar 11, 2026
  2. added
    interpreter-core(Objects, Python, Grammar, and Parser dirs)
    type-crashA hard crash of the interpreter, possibly with a core dump
    and removed
    type-bugAn unexpected behavior, bug, or error
    on Mar 11, 2026
  3. sergey-miryanov commented on Mar 11, 2026

    @sergey-miryanov
    Contributor

    @fuhsnn Would you like open a PR?

  4. added a commit that references this issue on Mar 11, 2026
  5. added a commit that references this issue on Mar 13, 2026
  6. added a commit that references this issue on Mar 13, 2026
  7. vstinner commented on Mar 13, 2026

    @vstinner
    Member

    @fuhsnn: I'm curious, how did you spot this bug?

  8. added a commit that references this issue on Mar 13, 2026
  9. fuhsnn commented on Mar 13, 2026

    @fuhsnn
    ContributorAuthor

    I was playing with disabling VLA support in slimcc (and defined __STDC_NO_VLA__ accordingly), saw test_faulthandler failing because of the change then tracked down the cause, just some nerdy fun (also found a jemalloc bug this way).

  10. added a commit that references this issue on Apr 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    interpreter-core(Objects, Python, Grammar, and Parser dirs)type-crashA hard crash of the interpreter, possibly with a core dump

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions