Skip to content

Backport msgpack fix for CVE-2026-57585 to vendored msgpack - #127

Merged
honnibal merged 1 commit into
v2.xfrom
fix/msgpack-cve-2026-57585
Sep 27, 2026
Merged

honnibal merged 1 commit into
v2.xfrom
fix/msgpack-cve-2026-57585

Conversation

@honnibal

Copy link
Copy Markdown
Member

Fixes CVE-2026-57585 (GHSA-6v7p-g79w-8964) in the vendored msgpack: reusing an Unpacker after a failed unpack resumed from a corrupt parser context and could crash the process.

This ports upstream msgpack-python commit 2c56ddb into srsly/msgpack/unpack_template.h and _unpacker.pyx. The fork's callbacks have the same reference-ownership semantics as upstream, so the patch applies as-is:

  • unpack_clear releases every stack entry (including pending map keys) and re-initialises the context
  • unpack_construct / unpack_skip clear the context when they fail
  • Unpacker._unpack clears the context before raising
  • map_key is reset once map_item has consumed it

Behaviour only changes after an error, when an Unpacker now resumes from a clean state. The high-level helpers (srsly.msgpack_loads etc.) create a fresh unpacker per call and are unaffected.

Tests: upstream's regression tests are added as new test functions, and no existing tests are changed. Without the fix, test_unpacker_should_not_crash_after_exception kills the interpreter and test_unpacker_usable_after_exception fails.

Closes #124.

馃 Generated with Claude Code

Reusing an Unpacker after a failed unpack resumed from a corrupt parser
context and could crash the process. Port upstream msgpack-python commit
2c56ddb: unpack_clear now releases the whole stack and re-initialises the
context, unpack_construct/unpack_skip clear on failure, Unpacker._unpack
clears before raising, and map_key is reset once consumed.

Closes #124.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@honnibal
honnibal merged commit 8a8224a into v2.x Sep 27, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant