Visitar URL original
syslog issues · Issue #95041 · python/cpython · GitHub
Skip to content

syslog issues #95041

Description

@serhiy-storchaka

There are several issues with corner cases in syslog.openlog().

  • syslog_get_argv() swallows exceptions, but not in all cases.
  • if ident is non UTF-8 encodable, syslog.openlog() fails after setting the global reference to ident. Now the C string saved internally in the previous call to openlog() points to the freed memory.
  • PySys_Audit() can crash if ident is NULL.
  • There may be a race condition with syslog.syslog(), because the global reference to ident is decrefed before setting the new value.

And, since syslog.syslog() releases the GIL, there may be a race condition syslog.syslog() with syslog.openlog() and syslog.closelog() which can decref the global reference to ident.

P.S. @noamcohen97 noticed yet one issue in syslog.syslog() (potential returning a value from a function while an exception is set #95012 (comment)) and fixed it.

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    3.11only security fixes
    3.12only security fixes
    on Jul 20, 2022
  2. added a commit that references this issue on Jul 20, 2022
  3. serhiy-storchaka commented on Jul 25, 2022

    @serhiy-storchaka
    Author
  4. arhadthedev commented on Jul 25, 2022

    @arhadthedev
  5. added a commit that references this issue on Jul 26, 2022
  6. added a commit that references this issue on Jul 26, 2022
  7. added 2 commits that reference this issue on Jul 26, 2022
  8. added a commit that references this issue on Jul 26, 2022
  9. added a commit that references this issue on Jul 26, 2022
  10. added 2 commits that reference this issue on Jul 26, 2022
  11. erlend-aasland commented on Jul 26, 2022

    @erlend-aasland
    Contributor

    I'm keeping this open until you decide about the NEWS entry, Serhiy. I'll mark it pending close, though.

  12. added
    pendingThe issue will be closed if no feedback is provided
    on Jul 26, 2022
  13. added 2 commits that reference this issue on Jul 26, 2022
  14. erlend-aasland commented on Jul 27, 2022

    @erlend-aasland
    Contributor

    (Ooops, sorry; pressed the wrong button)

  15. hauntsaninja commented on Oct 12, 2022

    @hauntsaninja
    Contributor

    We kept this open based on #95264 (comment)

    It looks like Serhiy added the tests in #97953 but chose not to add a changelog entry, so I think we can close this out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

3.10 (EOL)end of life3.11only security fixes3.12only security fixespendingThe issue will be closed if no feedback is providedtype-bugAn unexpected behavior, bug, or error

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions