Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 38 additions & 0 deletions Lib/test/test_zoneinfo/test_zoneinfo.py
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
import struct
import tempfile
import unittest
import sys
from datetime import date, datetime, time, timedelta, timezone
from functools import cached_property

Expand Down Expand Up @@ -2253,6 +2254,43 @@ def _Pacific_Kiritimati():
_ZONEDUMP_DATA = None
_FIXED_OFFSET_ZONES = None

class CZoneInfoSanityTest(CZoneInfoTest):
"""gh-125318: custom non-PyDateTime types could cause out-of-bounds read"""

class CustomDateTime:
def __init__(self, year, month, day, hour=0, minute=0, second=0):
self.ordinal = date(year, month, day).toordinal()
self.hour = hour
self.minute = minute
self.second = second

def toordinal(self):
return self.ordinal

def _spray(self, depth):
if depth == 0:
return None
self._spray(depth - 1)

def test_find_ttinfo_sanity(self):
RECURSION_LIMIT = 1000000
SPRAY_TIMES = 10000
CHECK_TIMES = 10000

# spray some garbage on the stack
saved_limit = sys.getrecursionlimit()
sys.setrecursionlimit(RECURSION_LIMIT)
self._spray(SPRAY_TIMES)
sys.setrecursionlimit(saved_limit)

for _ in range(CHECK_TIMES):
zi = self.klass("UTC")
dt = self.CustomDateTime(2024, 10, 22, 10, 24, 20)
try:
zi.utcoffset(dt)
except MemoryError:
continue


if __name__ == '__main__':
unittest.main()
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add sanity check in :mod:`zoneinfo` to mitigate out-of-bounds read.
10 changes: 9 additions & 1 deletion Modules/_zoneinfo.c
Original file line number Diff line number Diff line change
Expand Up @@ -2205,7 +2205,15 @@ find_ttinfo(zoneinfo_state *state, PyZoneInfo_ZoneInfo *self, PyObject *dt)
}

unsigned char fold = PyDateTime_DATE_GET_FOLD(dt);
assert(fold < 2);
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assertion here is unwanted, even though it's optimized out for some mysterious reason.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assertions are always optimized out :)


// gh-125318: out-of-bounds sanity check on non-PyDateTime types
if (fold >= 2) {
PyErr_Format(PyExc_MemoryError,
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't use a MemoryError:

Suggested change
PyErr_Format(PyExc_MemoryError,
PyErr_Format(PyExc_ValueError,

"find_ttinfo: sanity check failed, fold = %d, expected "
"only 0 or 1", fold);
Comment on lines +2212 to +2213
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't particularly useful to the user. Could you give more information on what they should do? (This is almost as bad as an assertion failure--we're almost certain to get reports about this.)

return NULL;
}

int64_t *local_transitions = self->trans_list_wall[fold];
size_t num_trans = self->num_transitions;

Expand Down
Loading