Skip to content

gh-156293: Use-after-free for server-side SSLContext with sni_callback - #158504

Merged
hugovk merged 1 commit into
python:mainfrom
sethmlarson:uaf-ssl-context-sni-callback
Sep 30, 2026
Merged

hugovk merged 1 commit into
python:mainfrom
sethmlarson:uaf-ssl-context-sni-callback

Conversation

@sethmlarson

@sethmlarson sethmlarson commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

I believe this needs to be backported manually beyond 3.13? (cc @gpshead) I can create those PRs.

@sethmlarson sethmlarson added the type-security A security issue label Sep 30, 2026
@sethmlarson sethmlarson added release-blocker topic-SSL needs backport to 3.15 pre-release feature fixes, bugs and security fixes labels Sep 30, 2026
@sethmlarson sethmlarson added needs backport to 3.13 only security fixes needs backport to 3.14 bugs and security fixes labels Sep 30, 2026
@read-the-docs-community

read-the-docs-community Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Documentation build overview

📚 cpython-previews | 🛠️ Build #34855142 | 📁 Comparing 0f63c2a against main (069c74a)

  🔍 Preview build  

2 files changed
± library/ssl.html
± whatsnew/changelog.html

@Yhg1s

Yhg1s commented Sep 30, 2026

Copy link
Copy Markdown
Member

We should probably still set the backport tags to make it clear it should get backported that far, even if the automatic one is likely to fail.

@sethmlarson sethmlarson changed the title gh-158446: Use-after-free for server-side SSLContext with sni_callback gh-156293: Use-after-free for server-side SSLContext with sni_callback Sep 30, 2026
…allback

Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
@sethmlarson
sethmlarson force-pushed the uaf-ssl-context-sni-callback branch from 402015d to 0f63c2a Compare September 30, 2026 14:57
@sethmlarson

Copy link
Copy Markdown
Contributor Author

I set the wrong GitHub issue, so I've had to force-push to fix that on the commit and in the GH PR (too many reserved, will have to be more careful about that in the future).

@sethmlarson sethmlarson added needs backport to 3.11 only security fixes needs backport to 3.12 only security fixes labels Sep 30, 2026
@hugovk
hugovk enabled auto-merge (squash) September 30, 2026 15:10
@hugovk
hugovk merged commit 34a53dc into python:main Sep 30, 2026
58 checks passed
@miss-islington-app

Copy link
Copy Markdown

Thanks @sethmlarson for the PR, and @hugovk for merging it 🌮🎉.. I'm working now to backport this PR to: 3.11, 3.12, 3.13, 3.14, 3.15.
🐍🍒⛏🤖

@miss-islington-app

Copy link
Copy Markdown

Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to 3.13 due to a conflict.
Please backport using cherry_picker on command line.

cherry_picker 34a53dce8174da2fceb12fe084a4def02a10053d 3.13

@bedevere-app

bedevere-app Bot commented Sep 30, 2026

Copy link
Copy Markdown

GH-158514 is a backport of this pull request to the 3.15 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.15 pre-release feature fixes, bugs and security fixes label Sep 30, 2026
@miss-islington-app

Copy link
Copy Markdown

Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to 3.12 due to a conflict.
Please backport using cherry_picker on command line.

cherry_picker 34a53dce8174da2fceb12fe084a4def02a10053d 3.12

@bedevere-app

bedevere-app Bot commented Sep 30, 2026

Copy link
Copy Markdown

GH-158515 is a backport of this pull request to the 3.14 branch.

@miss-islington-app

Copy link
Copy Markdown

Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to 3.11 due to a conflict.
Please backport using cherry_picker on command line.

cherry_picker 34a53dce8174da2fceb12fe084a4def02a10053d 3.11

@bedevere-app bedevere-app Bot removed the needs backport to 3.14 bugs and security fixes label Sep 30, 2026
hugovk pushed a commit that referenced this pull request Sep 30, 2026
…callback (GH-158504) (#158515)

Co-authored-by: Seth Larson <seth@python.org>
Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
hugovk pushed a commit that referenced this pull request Sep 30, 2026
…callback (GH-158504) (#158514)

Co-authored-by: Seth Larson <seth@python.org>
Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
@gpshead

gpshead commented Sep 30, 2026

Copy link
Copy Markdown
Member

I have a stack of backport PR branches ready for this, they were pushed to the GHSA private fork IIRC, see the GHSA

@gpshead

gpshead commented Sep 30, 2026

Copy link
Copy Markdown
Member

See my gpshead fork's gh-156293-ssl-sni-callback-* branches. for the backports, just pushed them there.

@hugovk

hugovk commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

We already have 3.12-3.15 backports merged.

I'll open 3.10-3.11 backports from the ready forks at gh-156293-ssl-sni-callback-*.

Edit: I don't need to, Greg did it :)

@bedevere-app

bedevere-app Bot commented Sep 30, 2026

Copy link
Copy Markdown

GH-158523 is a backport of this pull request to the 3.11 branch.

@bedevere-app bedevere-app Bot removed the needs backport to 3.11 only security fixes label Sep 30, 2026
@bedevere-app

bedevere-app Bot commented Sep 30, 2026

Copy link
Copy Markdown

GH-158524 is a backport of this pull request to the 3.10 branch.

pablogsal pushed a commit that referenced this pull request Oct 1, 2026
…callback (GH-158504) (#158524)

* [3.10] gh-156293: ssl: do not call the servername callback through a released SSLContext

The servername (SNI) callback located its SSLContext through a borrowed
pointer registered with OpenSSL, which can outlive the SSLContext object.
Look the context up from the SSL object instead, and unregister the
callback when the context is deallocated.

Backport of 87665c9,
adapted to this branch's servername callback code.

* [3.10] gh-156293: Document sni_callback dispatch after a context switch
pablogsal pushed a commit that referenced this pull request Oct 1, 2026
…callback (GH-158504) (#158523)

* [3.11] gh-156293: ssl: do not call the servername callback through a released SSLContext

The servername (SNI) callback located its SSLContext through a borrowed
pointer registered with OpenSSL, which can outlive the SSLContext object.
Look the context up from the SSL object instead, and unregister the
callback when the context is deallocated.

Backport of 87665c9,
adapted to this branch's servername callback code.

* [3.11] gh-156293: Document sni_callback dispatch after a context switch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Development

Successfully merging this pull request may close these issues.

4 participants