Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix: use-after-free in get_data_from_buffer
  • Loading branch information
KowalskiThomas committed May 26, 2026
commit eae29a954e11261313fc4ba1ef05d91faa3bb4a0
4 changes: 1 addition & 3 deletions msgpack/_unpacker.pyx
Original file line number Diff line number Diff line change
Expand Up @@ -130,9 +130,7 @@ cdef inline int get_data_from_buffer(object obj,
# create a contiguous copy and get buffer
contiguous = PyMemoryView_GetContiguous(obj, PyBUF_READ, b'C')
PyObject_GetBuffer(contiguous, view, PyBUF_SIMPLE)
# view must hold the only reference to contiguous,
# so memory is freed when view is released
Py_DECREF(contiguous)

Comment thread
KowalskiThomas marked this conversation as resolved.
buffer_len[0] = view.len
buf[0] = <char*> view.buf
return 1
Expand Down
3 changes: 2 additions & 1 deletion msgpack/fallback.py
Original file line number Diff line number Diff line change
Expand Up @@ -328,7 +328,8 @@ def feed(self, next_bytes):
self._buf_checkpoint = 0

# Use extend here: INPLACE_ADD += doesn't reliably typecast memoryview in jython
self._buffer.extend(view)
# tobytes ensures compatibility with non-contiguous memoryviews
self._buffer.extend(view.tobytes())
view.release()
Comment thread
KowalskiThomas marked this conversation as resolved.

def _consume(self):
Expand Down
Loading