python / python/cpython

vars's mapping proxy can expose internal dictionary even for built-in types

Abierto
#152,405 18 comentarios 3 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

interpreter-core type-crash
Lenguaje dominante
Python
Estrellas
77.2k
Forks
35.9k
Métricas de merge de PR
Métricas de PR pendientes

Descripción

Bug report

Bug description:

By creating a type or class with a definition of __eq__ that simply returns the other object, it is possible to access the underlying dictionary behind the mapping proxy returned by vars.

This can be (ab)used to bypass mutability restrictions on built-in types, as the example below shows:

class Evil:
    def __eq__(self, other):
        return other

# less readable version of Evil:
# type("Evil", (), {"__eq__": lambda self, other: other})

# this statement adds a method `prepend` to the built-in type `list`
# 1. vars(list) == Evil() returns the underlying dictionary of `list`
# 2. we can then use the dict[name] = value statement to set the attribute `name`
(vars(list) == Evil())["prepend"] = lambda self, value: self.insert(0, value)

x = [3, 5, 2]
x.prepend(7)

print(x)  # [7, 3, 5, 2]

This can be used to cause a segmentation fault:

# reusing Evil from earlier
(vars(type) == Evil())["__instancecheck__"] = lambda *_: False
# fish: Job 1, 'python' terminated by signal SIGSEGV

No FFI, not a single line of C code required.

This also works on CPython 2.7 and 3.9. It might even be possible to do on even earlier versions.

Disclaimer
I have independently discovered this by myself (no LLM).

CPython versions tested on:

3.14, 3.12, 3.11

Operating systems tested on:

Linux

Linked PRs
  • gh-152449
  • gh-152483
  • gh-152489
  • gh-153670

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Start by reproducing the vars(list) == Evil() and vars(type) == Evil() examples on the listed CPython versions. Review linked PRs gh-152449, gh-152483, gh-152489, and gh-153670 to understand the proposed fix and its validation; done means the mapping proxy no longer exposes a mutable internal dictionary or permits the demonstrated crash.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bien especificado
Aptitud para principiantes
20/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.