CPython 3.13-3.15 concurrency and memory-safety issue reports
Personne n'a encore pris cette issue.
- Langage dominant
- Python
- Étoiles
- 77.2k
- Forks
- 35.9k
- Métriques de merge des PR
- Métriques de PR en attente
Description
Hello!
We are a team conducting Python security research. Recently, we investigated concurrency behavior in CPython and identified a set of reproducible correctness, concurrency, and memory-safety issues.
We evaluated free-threaded (FT) and conventional GIL-enabled builds separately. The confirmed findings cover CPython 3.13, 3.14, and 3.15. Across both build modes and releases, we identified 142 unique bugs in total.
Of these, 139 were confirmed in free-threaded builds and 34 were confirmed in conventional GIL-enabled builds. These two groups overlap: 31 bugs were confirmed in both build modes, while 3 were confirmed only in GIL-enabled builds.
The findings affect 29 library or extension components, 61 logical components, and 75 C source files. They primarily include Race Condition (CWE-362), TOCTOU Race Condition (CWE-367), Use After Free (CWE-416), and Improper Control of a Resource Through its Lifetime (CWE-664).
We have prepared a GitHub repository containing detailed bug reports, PoCs, and a comprehensive summary:
https://github.com/BaihongChen/cpython-concurrency-bugs
Complete component coverage
| Component | Category | 3.13 | 3.14 | 3.15 |
|---|---|---|---|---|
_remote_debugging |
Library/extension | — | — | ✓ |
array |
Library/extension | ✓ | ✓ | ✓ |
asyncio |
Library/extension | ✓ | — | — |
atexit |
Library/extension | ✓ | — | — |
collections |
Library/extension | ✓ | ✓ | ✓ |
compression.zstd |
Library/extension | — | ✓ | ✓ |
csv |
Library/extension | ✓ | — | — |
ctypes |
Library/extension | ✓ | ✓ | ✓ |
curses |
Library/extension | — | ✓ | — |
decimal |
Library/extension | ✓ | ✓ | — |
_suggestions / error suggestions |
Library/extension | ✓ | ✓ | — |
functools |
Library/extension | ✓ | ✓ | ✓ |
io |
Library/extension | ✓ | ✓ | — |
itertools |
Library/extension | ✓ | ✓ | ✓ |
json |
Library/extension | ✓ | ✓ | — |
locale |
Library/extension | — | ✓ | — |
| multibyte codecs | Library/extension | ✓ | ✓ | ✓ |
os |
Library/extension | ✓ | ✓ | ✓ |
pickle |
Library/extension | ✓ | ✓ | ✓ |
pyexpat |
Library/extension | ✓ | ✓ | ✓ |
re |
Library/extension | ✓ | ✓ | ✓ |
select |
Library/extension | ✓ | ✓ | ✓ |
sqlite3 |
Library/extension | ✓ | ✓ | ✓ |
ssl |
Library/extension | ✓ | ✓ | ✓ |
struct |
Library/extension | ✓ | ✓ | ✓ |
subprocess |
Library/extension | ✓ | ✓ | ✓ |
syslog |
Library/extension | ✓ | ✓ | ✓ |
termios |
Library/extension | ✓ | ✓ | ✓ |
tkinter |
Library/extension | ✓ | ✓ | ✓ |
xml.etree.ElementTree |
Library/extension | ✓ | ✓ | ✓ |
bytearray |
Built-in/core | ✓ | ✓ | ✓ |
bytes |
Built-in/core | ✓ | ✓ | ✓ |
| call protocol | Built-in/core | ✓ | ✓ | ✓ |
collections.OrderedDict |
Built-in/core | ✓ | ✓ | ✓ |
dict |
Built-in/core | ✓ | ✓ | ✓ |
| exceptions | Built-in/core | ✓ | ✓ | ✓ |
float |
Built-in/core | ✓ | ✓ | ✓ |
| frame | Built-in/core | ✓ | ✓ | ✓ |
| function | Built-in/core | ✓ | ✓ | ✓ |
| generator | Built-in/core | — | ✓ | — |
int |
Built-in/core | ✓ | ✓ | ✓ |
memoryview |
Built-in/core | ✓ | ✓ | ✓ |
| module | Built-in/core | ✓ | ✓ | ✓ |
| object protocol | Built-in/core | ✓ | ✓ | ✓ |
str |
Built-in/core | ✓ | ✓ | ✓ |
| struct sequence | Built-in/core | ✓ | ✓ | ✓ |
type |
Built-in/core | ✓ | ✓ | — |
ast |
Runtime/compiler | ✓ | ✓ | ✓ |
| C argument parsing | Runtime/compiler | ✓ | ✓ | ✓ |
| codec registry | Runtime/compiler | ✓ | ✓ | ✓ |
| compile/exec | Runtime/compiler | ✓ | ✓ | ✓ |
| compiler/evaluator | Runtime/compiler | ✓ | ✓ | ✓ |
contextvars |
Runtime/compiler | ✓ | ✓ | ✓ |
| cross-interpreter data | Runtime/compiler | ✓ | ✓ | ✓ |
| garbage collection | Runtime/compiler | ✓ | ✓ | ✓ |
| import machinery | Runtime/compiler | ✓ | ✓ | ✓ |
marshal |
Runtime/compiler | ✓ | ✓ | ✓ |
PyConfig |
Runtime/compiler | ✓ | ✓ | ✓ |
| runtime finalization | Runtime/compiler | ✓ | ✓ | ✓ |
sys |
Runtime/compiler | ✓ | ✓ | ✓ |
| traceback | Runtime/compiler | ✓ | ✓ | ✓ |
| warnings | Runtime/compiler | ✓ | — | — |
We hope these issues can be further confirmed and fixed in future releases. Thank you!
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez dans le dépôt lié cpython-concurrency-bugs, lisez ses rapports détaillés, ses PoCs et son résumé, puis sélectionnez un problème reproductible plutôt que de traiter l’ensemble. Suivez ce problème jusqu’au composant CPython et au fichier source C concernés, puis utilisez son PoC pour confirmer le problème ; le travail est terminé lorsque le bug spécifique est corrigé et que le PoC ne le reproduit plus.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- c, python
- Domaine
- compilers, security
- Type d'issue
- Bug
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Active
- Clarté
- À clarifier
- Accessibilité débutants
- 18/100