Visitar URL original
gh-158923: Fix use-after-free in xibufferview_getbuf() by christianaurichzm · Pull Request #159005 · python/cpython · GitHub
Skip to content

gh-158923: Fix use-after-free in xibufferview_getbuf() - #159005

Open
christianaurichzm wants to merge 1 commit into
python:mainfrom
christianaurichzm:gh-158923-xibufferview-getbuf
Open

christianaurichzm wants to merge 1 commit into
python:mainfrom
christianaurichzm:gh-158923-xibufferview-getbuf

Conversation

@christianaurichzm

@christianaurichzm christianaurichzm commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #158923

xibufferview_getbuf() sets view->obj without an incref. That's fine for _memoryview_from_xid(), which passes its own reference to the new memoryview, but the wrapper is also visible from Python as mv.obj. So bytes(mv.obj), memoryview(mv.obj) etc. release a reference they never got, the wrapper is freed, and the shared memoryview still points to it.

Fix: incref in xibufferview_getbuf() like any other getbuffer, and decref in _memoryview_from_xid() after creating the memoryview.

Tested on a debug build: the reproducer from the issue and the new test both segfault without the patch and pass with it (the test also passes with -R 3:3). test_interpreters, test__interpreters, test__interpchannels, test_crossinterp and test_concurrent_futures.test_interpreter_pool pass.

xibufferview_getbuf() didn't incref view->obj. The wrapper is exposed
as mv.obj, so something like bytes(mv.obj) released a reference it
never took, and the wrapper could be freed while the shared memoryview
was still using it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

_interpreters xibufferview_getbuf missing INCREF: shared-memoryview UAF

1 participant