CPython 3.13-3.15 concurrency and memory-safety issue reports
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 35.9k
- PR merge metrics
- PR metrics pending
Description
Hello!
We are a team conducting Python security research. Recently, we investigated concurrency behavior in CPython and identified a set of reproducible correctness, concurrency, and memory-safety issues.
We evaluated free-threaded (FT) and conventional GIL-enabled builds separately. The confirmed findings cover CPython 3.13, 3.14, and 3.15. Across both build modes and releases, we identified 142 unique bugs in total.
Of these, 139 were confirmed in free-threaded builds and 34 were confirmed in conventional GIL-enabled builds. These two groups overlap: 31 bugs were confirmed in both build modes, while 3 were confirmed only in GIL-enabled builds.
The findings affect 29 library or extension components, 61 logical components, and 75 C source files. They primarily include Race Condition (CWE-362), TOCTOU Race Condition (CWE-367), Use After Free (CWE-416), and Improper Control of a Resource Through its Lifetime (CWE-664).
We have prepared a GitHub repository containing detailed bug reports, PoCs, and a comprehensive summary:
https://github.com/BaihongChen/cpython-concurrency-bugs
Complete component coverage
| Component | Category | 3.13 | 3.14 | 3.15 |
|---|---|---|---|---|
_remote_debugging |
Library/extension | — | — | ✓ |
array |
Library/extension | ✓ | ✓ | ✓ |
asyncio |
Library/extension | ✓ | — | — |
atexit |
Library/extension | ✓ | — | — |
collections |
Library/extension | ✓ | ✓ | ✓ |
compression.zstd |
Library/extension | — | ✓ | ✓ |
csv |
Library/extension | ✓ | — | — |
ctypes |
Library/extension | ✓ | ✓ | ✓ |
curses |
Library/extension | — | ✓ | — |
decimal |
Library/extension | ✓ | ✓ | — |
_suggestions / error suggestions |
Library/extension | ✓ | ✓ | — |
functools |
Library/extension | ✓ | ✓ | ✓ |
io |
Library/extension | ✓ | ✓ | — |
itertools |
Library/extension | ✓ | ✓ | ✓ |
json |
Library/extension | ✓ | ✓ | — |
locale |
Library/extension | — | ✓ | — |
| multibyte codecs | Library/extension | ✓ | ✓ | ✓ |
os |
Library/extension | ✓ | ✓ | ✓ |
pickle |
Library/extension | ✓ | ✓ | ✓ |
pyexpat |
Library/extension | ✓ | ✓ | ✓ |
re |
Library/extension | ✓ | ✓ | ✓ |
select |
Library/extension | ✓ | ✓ | ✓ |
sqlite3 |
Library/extension | ✓ | ✓ | ✓ |
ssl |
Library/extension | ✓ | ✓ | ✓ |
struct |
Library/extension | ✓ | ✓ | ✓ |
subprocess |
Library/extension | ✓ | ✓ | ✓ |
syslog |
Library/extension | ✓ | ✓ | ✓ |
termios |
Library/extension | ✓ | ✓ | ✓ |
tkinter |
Library/extension | ✓ | ✓ | ✓ |
xml.etree.ElementTree |
Library/extension | ✓ | ✓ | ✓ |
bytearray |
Built-in/core | ✓ | ✓ | ✓ |
bytes |
Built-in/core | ✓ | ✓ | ✓ |
| call protocol | Built-in/core | ✓ | ✓ | ✓ |
collections.OrderedDict |
Built-in/core | ✓ | ✓ | ✓ |
dict |
Built-in/core | ✓ | ✓ | ✓ |
| exceptions | Built-in/core | ✓ | ✓ | ✓ |
float |
Built-in/core | ✓ | ✓ | ✓ |
| frame | Built-in/core | ✓ | ✓ | ✓ |
| function | Built-in/core | ✓ | ✓ | ✓ |
| generator | Built-in/core | — | ✓ | — |
int |
Built-in/core | ✓ | ✓ | ✓ |
memoryview |
Built-in/core | ✓ | ✓ | ✓ |
| module | Built-in/core | ✓ | ✓ | ✓ |
| object protocol | Built-in/core | ✓ | ✓ | ✓ |
str |
Built-in/core | ✓ | ✓ | ✓ |
| struct sequence | Built-in/core | ✓ | ✓ | ✓ |
type |
Built-in/core | ✓ | ✓ | — |
ast |
Runtime/compiler | ✓ | ✓ | ✓ |
| C argument parsing | Runtime/compiler | ✓ | ✓ | ✓ |
| codec registry | Runtime/compiler | ✓ | ✓ | ✓ |
| compile/exec | Runtime/compiler | ✓ | ✓ | ✓ |
| compiler/evaluator | Runtime/compiler | ✓ | ✓ | ✓ |
contextvars |
Runtime/compiler | ✓ | ✓ | ✓ |
| cross-interpreter data | Runtime/compiler | ✓ | ✓ | ✓ |
| garbage collection | Runtime/compiler | ✓ | ✓ | ✓ |
| import machinery | Runtime/compiler | ✓ | ✓ | ✓ |
marshal |
Runtime/compiler | ✓ | ✓ | ✓ |
PyConfig |
Runtime/compiler | ✓ | ✓ | ✓ |
| runtime finalization | Runtime/compiler | ✓ | ✓ | ✓ |
sys |
Runtime/compiler | ✓ | ✓ | ✓ |
| traceback | Runtime/compiler | ✓ | ✓ | ✓ |
| warnings | Runtime/compiler | ✓ | — | — |
We hope these issues can be further confirmed and fixed in future releases. Thank you!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in the linked cpython-concurrency-bugs repository, reading its detailed reports, PoCs, and summary to select one reproducible finding rather than addressing the full set. Trace that finding into the affected CPython component and C source file, then use its PoC to confirm the issue; done means the specific bug is fixed and the PoC no longer reproduces.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, python
- Domain
- compilers, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 18/100