python / python/cpython

Dialog about overrun of a stack-based buffer on Windows Server 2022 (caused by `asyncio` / `socket`)

Abierto
#145,899 5 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

extension-modules OS-windows topic-socket type-crash
Lenguaje dominante
Python
Estrellas
77.2k
Forks
35.9k
Métricas de merge de PR
Métricas de PR pendientes

Descripción

Crash report

What happened?

On Windows Server 2022, when exiting a Python process, we sporadically get a dialog with the title "python.exe - System Error", which reads "The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application."

We do not get this error with Windows Server 2019.

The issue is very sporadically. Even with the following reproducers, we only experience the issue every 1,000 to 100,000 runs on our systems.

Our initial reproducer was:

import asyncio  
async def f():  
    pass
asyncio.run(f())

We could narrow it down further to:

import socket
socket.socketpair()

(The issue does also occur if I close the sockets returned from socketpair.)

The issue can also be reproduced with the following snippet extracted from socket.socketpair():

import socket

l = socket.socket()
l.bind(("127.0.0.1",0))
l.listen()

c = socket.socket()
c.setblocking(False)
try:
    c.connect(l.getsockname())
except BlockingIOError:
    pass

Setting the socket to unblocking seems to be essential. I could not reproduce the issue without setting it to unblocking.

Further, calling os._exit() prevents the issue. I digged a little further and found that not calling WSACleanup() in os_cleanup() in socketmodule.c prevents the issue.

CPython versions tested on:

3.11, 3.12, 3.13, 3.14

Operating systems tested on:

Windows

Output from running 'python -VV' on the command line:

No response

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Comienza en socketmodule.c, en os_cleanup(), centrándote en la llamada a WSACleanup(). Ejecuta repetidamente el reproductor mínimo con socketpair() o un socket no bloqueante en Windows Server 2022 y compara el comportamiento con Windows Server 2019. Se considera terminado cuando se haya identificado y corregido la ruta de apagado, de modo que ya no aparezca el cuadro de diálogo de stack-buffer-overrun.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
networking, operating-systems
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.