Skip to content

Commit 161b9dc

Browse files
committed
Revert "[3.15] gh-158583: Fix uninitialized memory read in bytes.fromhex() (GH-158584) (#158691)"
This reverts commit 4f7af46.
1 parent f8afd33 commit 161b9dc

3 files changed

Lines changed: 8 additions & 21 deletions

File tree

‎Lib/test/test_bytes.py‎

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -508,15 +508,6 @@ def test_fromhex(self):
508508
self.type2test.fromhex(data)
509509
self.assertIn('at position %s' % pos, str(cm.exception))
510510

511-
# gh-158583: Check for out of bounds reads (uninitialized bytes).
512-
# Create an array from a list to not overallocate.
513-
a = array.array('B', list(b'1234 ')) # Py_ISSPACE() loop
514-
self.assertEqual(self.type2test.fromhex(a), b'\x12\x34')
515-
516-
a = array.array('B', list(b'12345')) # Missing second digit
517-
with self.assertRaises(ValueError):
518-
self.type2test.fromhex(a)
519-
520511
def test_hex(self):
521512
self.assertRaises(TypeError, self.type2test.hex)
522513
self.assertRaises(TypeError, self.type2test.hex, 1)

‎Misc/NEWS.d/next/Core_and_Builtins/2026-10-03-16-14-26.gh-issue-158583.7EUMvS.rst‎

Lines changed: 0 additions & 2 deletions
This file was deleted.

‎Objects/bytesobject.c‎

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2691,35 +2691,33 @@ _PyBytes_FromHex(PyObject *string, int use_bytearray)
26912691
if (Py_ISSPACE(*str)) {
26922692
do {
26932693
str++;
2694-
if (str >= end) {
2695-
goto done;
2696-
}
26972694
} while (Py_ISSPACE(*str));
2695+
if (str >= end)
2696+
break;
26982697
}
26992698

27002699
top = _PyLong_DigitValue[*str];
27012700
if (top >= 16) {
27022701
invalid_char = str - start;
27032702
goto error;
27042703
}
2705-
27062704
str++;
2707-
if (str >= end) {
2708-
invalid_char = -1;
2709-
goto error;
2710-
}
27112705

27122706
bot = _PyLong_DigitValue[*str];
27132707
if (bot >= 16) {
2714-
invalid_char = str - start;
2708+
/* Check if we had a second digit */
2709+
if (str >= end){
2710+
invalid_char = -1;
2711+
} else {
2712+
invalid_char = str - start;
2713+
}
27152714
goto error;
27162715
}
27172716
str++;
27182717

27192718
*buf++ = (unsigned char)((top << 4) + bot);
27202719
}
27212720

2722-
done:
27232721
if (view.obj != NULL) {
27242722
PyBuffer_Release(&view);
27252723
}

0 commit comments

Comments
 (0)