CPython 3.13-3.15 concurrency and memory-safety issue reports
Nessuno ha ancora preso questa issue.
- Lingua principale
- Python
- Stelle
- 77.2k
- Fork
- 35.9k
- Metriche di merge delle PR
- Metriche PR in attesa
Descrizione
Hello!
We are a team conducting Python security research. Recently, we investigated concurrency behavior in CPython and identified a set of reproducible correctness, concurrency, and memory-safety issues.
We evaluated free-threaded (FT) and conventional GIL-enabled builds separately. The confirmed findings cover CPython 3.13, 3.14, and 3.15. Across both build modes and releases, we identified 142 unique bugs in total.
Of these, 139 were confirmed in free-threaded builds and 34 were confirmed in conventional GIL-enabled builds. These two groups overlap: 31 bugs were confirmed in both build modes, while 3 were confirmed only in GIL-enabled builds.
The findings affect 29 library or extension components, 61 logical components, and 75 C source files. They primarily include Race Condition (CWE-362), TOCTOU Race Condition (CWE-367), Use After Free (CWE-416), and Improper Control of a Resource Through its Lifetime (CWE-664).
We have prepared a GitHub repository containing detailed bug reports, PoCs, and a comprehensive summary:
https://github.com/BaihongChen/cpython-concurrency-bugs
Complete component coverage
| Component | Category | 3.13 | 3.14 | 3.15 |
|---|---|---|---|---|
_remote_debugging |
Library/extension | — | — | ✓ |
array |
Library/extension | ✓ | ✓ | ✓ |
asyncio |
Library/extension | ✓ | — | — |
atexit |
Library/extension | ✓ | — | — |
collections |
Library/extension | ✓ | ✓ | ✓ |
compression.zstd |
Library/extension | — | ✓ | ✓ |
csv |
Library/extension | ✓ | — | — |
ctypes |
Library/extension | ✓ | ✓ | ✓ |
curses |
Library/extension | — | ✓ | — |
decimal |
Library/extension | ✓ | ✓ | — |
_suggestions / error suggestions |
Library/extension | ✓ | ✓ | — |
functools |
Library/extension | ✓ | ✓ | ✓ |
io |
Library/extension | ✓ | ✓ | — |
itertools |
Library/extension | ✓ | ✓ | ✓ |
json |
Library/extension | ✓ | ✓ | — |
locale |
Library/extension | — | ✓ | — |
| multibyte codecs | Library/extension | ✓ | ✓ | ✓ |
os |
Library/extension | ✓ | ✓ | ✓ |
pickle |
Library/extension | ✓ | ✓ | ✓ |
pyexpat |
Library/extension | ✓ | ✓ | ✓ |
re |
Library/extension | ✓ | ✓ | ✓ |
select |
Library/extension | ✓ | ✓ | ✓ |
sqlite3 |
Library/extension | ✓ | ✓ | ✓ |
ssl |
Library/extension | ✓ | ✓ | ✓ |
struct |
Library/extension | ✓ | ✓ | ✓ |
subprocess |
Library/extension | ✓ | ✓ | ✓ |
syslog |
Library/extension | ✓ | ✓ | ✓ |
termios |
Library/extension | ✓ | ✓ | ✓ |
tkinter |
Library/extension | ✓ | ✓ | ✓ |
xml.etree.ElementTree |
Library/extension | ✓ | ✓ | ✓ |
bytearray |
Built-in/core | ✓ | ✓ | ✓ |
bytes |
Built-in/core | ✓ | ✓ | ✓ |
| call protocol | Built-in/core | ✓ | ✓ | ✓ |
collections.OrderedDict |
Built-in/core | ✓ | ✓ | ✓ |
dict |
Built-in/core | ✓ | ✓ | ✓ |
| exceptions | Built-in/core | ✓ | ✓ | ✓ |
float |
Built-in/core | ✓ | ✓ | ✓ |
| frame | Built-in/core | ✓ | ✓ | ✓ |
| function | Built-in/core | ✓ | ✓ | ✓ |
| generator | Built-in/core | — | ✓ | — |
int |
Built-in/core | ✓ | ✓ | ✓ |
memoryview |
Built-in/core | ✓ | ✓ | ✓ |
| module | Built-in/core | ✓ | ✓ | ✓ |
| object protocol | Built-in/core | ✓ | ✓ | ✓ |
str |
Built-in/core | ✓ | ✓ | ✓ |
| struct sequence | Built-in/core | ✓ | ✓ | ✓ |
type |
Built-in/core | ✓ | ✓ | — |
ast |
Runtime/compiler | ✓ | ✓ | ✓ |
| C argument parsing | Runtime/compiler | ✓ | ✓ | ✓ |
| codec registry | Runtime/compiler | ✓ | ✓ | ✓ |
| compile/exec | Runtime/compiler | ✓ | ✓ | ✓ |
| compiler/evaluator | Runtime/compiler | ✓ | ✓ | ✓ |
contextvars |
Runtime/compiler | ✓ | ✓ | ✓ |
| cross-interpreter data | Runtime/compiler | ✓ | ✓ | ✓ |
| garbage collection | Runtime/compiler | ✓ | ✓ | ✓ |
| import machinery | Runtime/compiler | ✓ | ✓ | ✓ |
marshal |
Runtime/compiler | ✓ | ✓ | ✓ |
PyConfig |
Runtime/compiler | ✓ | ✓ | ✓ |
| runtime finalization | Runtime/compiler | ✓ | ✓ | ✓ |
sys |
Runtime/compiler | ✓ | ✓ | ✓ |
| traceback | Runtime/compiler | ✓ | ✓ | ✓ |
| warnings | Runtime/compiler | ✓ | — | — |
We hope these issues can be further confirmed and fixed in future releases. Thank you!
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia dal repository collegato cpython-concurrency-bugs, leggi i suoi report dettagliati, i PoC e il riepilogo, quindi seleziona un problema riproducibile invece di affrontare l’intero insieme. Segui quel problema fino al componente CPython e al file sorgente C interessati, quindi usa il relativo PoC per confermare il problema; il lavoro è completato quando il bug specifico è stato corretto e il PoC non lo riproduce più.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- c, python
- Ambito
- compilers, security
- Tipo di issue
- Bug
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Attiva
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 18/100