python / python/cpython

Out-of-bounds read in integrated mimalloc (fixed upstream)

Open
#134,070 1 comment 0 reactions 1 assignee View on GitHub

@colesbury is already working on this.

Since May 16, 2025.

3.13 3.14 3.15 interpreter-core type-bug
Dominant language
Python
Stars
77.2k
Forks
35.9k
PR merge metrics
PR metrics pending

Description

Bug report

Bug description:

The integrated mimalloc has out-of-bounds bug in the generic implementation of ctz/clz:
https://github.com/python/cpython/blob/6a2296329117463fd09abc73656f1d7b48076100/Include/internal/mimalloc/mimalloc/internal.h#L847-L870
On platforms with 64-bit UL, the multiplication in index calculation can grow much larger than array debruijn[].

It has been fixed in this upstream commit:
https://github.com/microsoft/mimalloc/commit/ed318471126918fce7caf0001cf1e0c78f95173e

CPython versions tested on:

3.14, CPython main branch, 3.13, 3.15

Operating systems tested on:

Linux

Linked PRs
  • gh-134149
  • gh-134157

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.