summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>2024-01-17 13:30:29 (GMT)
committerGitHub <noreply@github.com>2024-01-17 13:30:29 (GMT)
commit76d0c4b6885365a08e840d99ab948ab2b7c4a34e (patch)
tree9ea248e1edf988b22c41cbdcdbd56de0eaf2ca69
parentbda62c0b22f8266b515e9ebb64a6115947b9dd43 (diff)
downloadcpython-76d0c4b6885365a08e840d99ab948ab2b7c4a34e.zip
cpython-76d0c4b6885365a08e840d99ab948ab2b7c4a34e.tar.gz
cpython-76d0c4b6885365a08e840d99ab948ab2b7c4a34e.tar.bz2
[3.11] gh-104282: Fix null pointer dereference in `lzma._decode_filter_properties` (GH-104283) (GH-114182)
(cherry picked from commit 0154405350c272833bd51f68138223655e142a37) Co-authored-by: Radislav Chugunov <52372310+chgnrdv@users.noreply.github.com>
-rw-r--r--Lib/test/test_lzma.py8
-rw-r--r--Misc/NEWS.d/next/Library/2023-05-08-09-30-00.gh-issue-104282.h4c6Eb.rst3
-rw-r--r--Modules/_lzmamodule.c4
3 files changed, 14 insertions, 1 deletions
diff --git a/Lib/test/test_lzma.py b/Lib/test/test_lzma.py
index 49042d7..d2ae133 100644
--- a/Lib/test/test_lzma.py
+++ b/Lib/test/test_lzma.py
@@ -1409,6 +1409,14 @@ class MiscellaneousTestCase(unittest.TestCase):
self.assertEqual(filterspec["lc"], 3)
self.assertEqual(filterspec["dict_size"], 8 << 20)
+ # see gh-104282
+ filters = [lzma.FILTER_X86, lzma.FILTER_POWERPC,
+ lzma.FILTER_IA64, lzma.FILTER_ARM,
+ lzma.FILTER_ARMTHUMB, lzma.FILTER_SPARC]
+ for f in filters:
+ filterspec = lzma._decode_filter_properties(f, b"")
+ self.assertEqual(filterspec, {"id": f})
+
def test_filter_properties_roundtrip(self):
spec1 = lzma._decode_filter_properties(
lzma.FILTER_LZMA1, b"]\x00\x00\x80\x00")
diff --git a/Misc/NEWS.d/next/Library/2023-05-08-09-30-00.gh-issue-104282.h4c6Eb.rst b/Misc/NEWS.d/next/Library/2023-05-08-09-30-00.gh-issue-104282.h4c6Eb.rst
new file mode 100644
index 0000000..569ce66
--- /dev/null
+++ b/Misc/NEWS.d/next/Library/2023-05-08-09-30-00.gh-issue-104282.h4c6Eb.rst
@@ -0,0 +1,3 @@
+Fix null pointer dereference in :func:`lzma._decode_filter_properties`
+due to improper handling of BCJ filters with properties of zero length.
+Patch by Radislav Chugunov.
diff --git a/Modules/_lzmamodule.c b/Modules/_lzmamodule.c
index b572d8c..97453a2 100644
--- a/Modules/_lzmamodule.c
+++ b/Modules/_lzmamodule.c
@@ -494,7 +494,9 @@ build_filter_spec(const lzma_filter *f)
case LZMA_FILTER_ARMTHUMB:
case LZMA_FILTER_SPARC: {
lzma_options_bcj *options = f->options;
- ADD_FIELD(options, start_offset);
+ if (options) {
+ ADD_FIELD(options, start_offset);
+ }
break;
}
default: