From a1c6258d7e077f93fb34dc27f68091b76c9fac1e Mon Sep 17 00:00:00 2001 From: Victor Stinner Date: Mon, 7 Sep 2026 21:32:25 +0200 Subject: [PATCH] gh-156939: Fix struct.pack('0p', bytes) (GH-157071) If the Pascal string is empty (size=0), do not write the size prefix. Previously, a NUL byte was written outsize the buffer (buffer overflow). In practice, the write remains into allocated memory and is silently ignored: no memory is corrupted. (cherry picked from commit 23525c90f539f621c802f2725e91ff234a69e1e0) Co-authored-by: Victor Stinner --- Modules/_struct.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Modules/_struct.c b/Modules/_struct.c index 614512fe35f047d..788dd39164f68c7 100644 --- a/Modules/_struct.c +++ b/Modules/_struct.c @@ -2231,7 +2231,9 @@ s_pack_internal(PyStructObject *soself, PyObject *const *args, int offset, memcpy(res + 1, p, n); if (n > 255) n = 255; - *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char); + if (n > 0) { + *res = Py_SAFE_DOWNCAST(n, Py_ssize_t, unsigned char); + } } else { if (e->pack(state, res, v, e) < 0) { if (PyLong_Check(v) && PyErr_ExceptionMatches(PyExc_OverflowError))