Hello!
We are a team conducting Python security research. Recently, we investigated concurrency behavior in CPython and identified a set of reproducible correctness, concurrency, and memory-safety issues.
We evaluated free-threaded (FT) and conventional GIL-enabled builds separately. The confirmed findings cover CPython 3.13, 3.14, and 3.15. Across both build modes and releases, we identified 142 unique bugs in total.
Of these, 139 were confirmed in free-threaded builds and 34 were confirmed in conventional GIL-enabled builds. These two groups overlap: 31 bugs were confirmed in both build modes, while 3 were confirmed only in GIL-enabled builds.
The findings affect 29 library or extension components, 61 logical components, and 75 C source files. They primarily include Race Condition (CWE-362), TOCTOU Race Condition (CWE-367), Use After Free (CWE-416), and Improper Control of a Resource Through its Lifetime (CWE-664).
We have prepared a GitHub repository containing detailed bug reports, PoCs, and a comprehensive summary:
https://github.com/BaihongChen/cpython-concurrency-bugs
Complete component coverage
| Component |
Category |
3.13 |
3.14 |
3.15 |
_remote_debugging |
Library/extension |
— |
— |
✓ |
array |
Library/extension |
✓ |
✓ |
✓ |
asyncio |
Library/extension |
✓ |
— |
— |
atexit |
Library/extension |
✓ |
— |
— |
collections |
Library/extension |
✓ |
✓ |
✓ |
compression.zstd |
Library/extension |
— |
✓ |
✓ |
csv |
Library/extension |
✓ |
— |
— |
ctypes |
Library/extension |
✓ |
✓ |
✓ |
curses |
Library/extension |
— |
✓ |
— |
decimal |
Library/extension |
✓ |
✓ |
— |
_suggestions / error suggestions |
Library/extension |
✓ |
✓ |
— |
functools |
Library/extension |
✓ |
✓ |
✓ |
io |
Library/extension |
✓ |
✓ |
— |
itertools |
Library/extension |
✓ |
✓ |
✓ |
json |
Library/extension |
✓ |
✓ |
— |
locale |
Library/extension |
— |
✓ |
— |
| multibyte codecs |
Library/extension |
✓ |
✓ |
✓ |
os |
Library/extension |
✓ |
✓ |
✓ |
pickle |
Library/extension |
✓ |
✓ |
✓ |
pyexpat |
Library/extension |
✓ |
✓ |
✓ |
re |
Library/extension |
✓ |
✓ |
✓ |
select |
Library/extension |
✓ |
✓ |
✓ |
sqlite3 |
Library/extension |
✓ |
✓ |
✓ |
ssl |
Library/extension |
✓ |
✓ |
✓ |
struct |
Library/extension |
✓ |
✓ |
✓ |
subprocess |
Library/extension |
✓ |
✓ |
✓ |
syslog |
Library/extension |
✓ |
✓ |
✓ |
termios |
Library/extension |
✓ |
✓ |
✓ |
tkinter |
Library/extension |
✓ |
✓ |
✓ |
xml.etree.ElementTree |
Library/extension |
✓ |
✓ |
✓ |
bytearray |
Built-in/core |
✓ |
✓ |
✓ |
bytes |
Built-in/core |
✓ |
✓ |
✓ |
| call protocol |
Built-in/core |
✓ |
✓ |
✓ |
collections.OrderedDict |
Built-in/core |
✓ |
✓ |
✓ |
dict |
Built-in/core |
✓ |
✓ |
✓ |
| exceptions |
Built-in/core |
✓ |
✓ |
✓ |
float |
Built-in/core |
✓ |
✓ |
✓ |
| frame |
Built-in/core |
✓ |
✓ |
✓ |
| function |
Built-in/core |
✓ |
✓ |
✓ |
| generator |
Built-in/core |
— |
✓ |
— |
int |
Built-in/core |
✓ |
✓ |
✓ |
memoryview |
Built-in/core |
✓ |
✓ |
✓ |
| module |
Built-in/core |
✓ |
✓ |
✓ |
| object protocol |
Built-in/core |
✓ |
✓ |
✓ |
str |
Built-in/core |
✓ |
✓ |
✓ |
| struct sequence |
Built-in/core |
✓ |
✓ |
✓ |
type |
Built-in/core |
✓ |
✓ |
— |
ast |
Runtime/compiler |
✓ |
✓ |
✓ |
| C argument parsing |
Runtime/compiler |
✓ |
✓ |
✓ |
| codec registry |
Runtime/compiler |
✓ |
✓ |
✓ |
| compile/exec |
Runtime/compiler |
✓ |
✓ |
✓ |
| compiler/evaluator |
Runtime/compiler |
✓ |
✓ |
✓ |
contextvars |
Runtime/compiler |
✓ |
✓ |
✓ |
| cross-interpreter data |
Runtime/compiler |
✓ |
✓ |
✓ |
| garbage collection |
Runtime/compiler |
✓ |
✓ |
✓ |
| import machinery |
Runtime/compiler |
✓ |
✓ |
✓ |
marshal |
Runtime/compiler |
✓ |
✓ |
✓ |
PyConfig |
Runtime/compiler |
✓ |
✓ |
✓ |
| runtime finalization |
Runtime/compiler |
✓ |
✓ |
✓ |
sys |
Runtime/compiler |
✓ |
✓ |
✓ |
| traceback |
Runtime/compiler |
✓ |
✓ |
✓ |
| warnings |
Runtime/compiler |
✓ |
— |
— |
We hope these issues can be further confirmed and fixed in future releases. Thank you!
Hello!
We are a team conducting Python security research. Recently, we investigated concurrency behavior in CPython and identified a set of reproducible correctness, concurrency, and memory-safety issues.
We evaluated free-threaded (FT) and conventional GIL-enabled builds separately. The confirmed findings cover CPython 3.13, 3.14, and 3.15. Across both build modes and releases, we identified 142 unique bugs in total.
Of these, 139 were confirmed in free-threaded builds and 34 were confirmed in conventional GIL-enabled builds. These two groups overlap: 31 bugs were confirmed in both build modes, while 3 were confirmed only in GIL-enabled builds.
The findings affect 29 library or extension components, 61 logical components, and 75 C source files. They primarily include Race Condition (CWE-362), TOCTOU Race Condition (CWE-367), Use After Free (CWE-416), and Improper Control of a Resource Through its Lifetime (CWE-664).
We have prepared a GitHub repository containing detailed bug reports, PoCs, and a comprehensive summary:
https://github.com/BaihongChen/cpython-concurrency-bugs
Complete component coverage
_remote_debuggingarrayasyncioatexitcollectionscompression.zstdcsvctypescursesdecimal_suggestions/ error suggestionsfunctoolsioitertoolsjsonlocaleospicklepyexpatreselectsqlite3sslstructsubprocesssyslogtermiostkinterxml.etree.ElementTreebytearraybytescollections.OrderedDictdictfloatintmemoryviewstrtypeastcontextvarsmarshalPyConfigsysWe hope these issues can be further confirmed and fixed in future releases. Thank you!