Issue #25021: Correctly make sure that product.__setstate__ does not access

invalid memory.
This commit is contained in:
Kristján Valur Jónsson 2015-09-12 15:20:54 +00:00
parent a82f77fb00
commit 102764a1f6
2 changed files with 20 additions and 2 deletions

View file

@ -2205,13 +2205,21 @@ product_setstate(productobject *lz, PyObject *state)
{
PyObject* indexObject = PyTuple_GET_ITEM(state, i);
Py_ssize_t index = PyLong_AsSsize_t(indexObject);
PyObject* pool;
Py_ssize_t poolsize;
if (index < 0 && PyErr_Occurred())
return NULL; /* not an integer */
pool = PyTuple_GET_ITEM(lz->pools, i);
poolsize = PyTuple_GET_SIZE(pool);
if (poolsize == 0) {
lz->stopped = 1;
Py_RETURN_NONE;
}
/* clamp the index */
if (index < 0)
index = 0;
else if (index > n-1)
index = n-1;
else if (index > poolsize-1)
index = poolsize-1;
lz->indices[i] = index;
}