From c70d59c52544d75ff50949e1c8167c6d55a19ba2 Mon Sep 17 00:00:00 2001 From: Kumar Aditya Date: Tue, 12 Nov 2024 18:01:34 +0530 Subject: [PATCH] gh-126405: fix use-after-free in `_asyncio.Future.remove_done_callback` (GH-126733) (cherry picked from commit 37c57dfad12744608091653fd753a1f770e2479b) Co-authored-by: Kumar Aditya --- Modules/_asynciomodule.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Modules/_asynciomodule.c b/Modules/_asynciomodule.c index 79896c6b9fdd92..7e2fe28423399f 100644 --- a/Modules/_asynciomodule.c +++ b/Modules/_asynciomodule.c @@ -994,8 +994,10 @@ _asyncio_Future_remove_done_callback_impl(FutureObj *self, PyTypeObject *cls, if (len == 1) { PyObject *cb_tup = PyList_GET_ITEM(self->fut_callbacks, 0); + Py_INCREF(cb_tup); int cmp = PyObject_RichCompareBool( PyTuple_GET_ITEM(cb_tup, 0), fn, Py_EQ); + Py_DECREF(cb_tup); if (cmp == -1) { return NULL; }