Crash report
del e.value on a StopIteration instance stores NULL into
PyStopIterationObject.value. The getter substitutes Py_None so it
looks fine at Python level, but two C consumers dereference it unconditionally.
Consumer 1 — genobject.c:818, gen_send_ex2:
value = Py_NewRef(((PyStopIterationObject *)exc)->value); // Py_NewRef(NULL) → SIGSEGV
Reproducer:
def gen():
yield 1
g = gen()
next(g)
e = StopIteration(99)
del e.value
g.send(None) # Segmentation fault (core dumped)
Consumer 2 — bytecodes.c:1971, CLEANUP_THROW:
value = PyStackRef_FromPyObjectNew(...) // assert(obj != NULL) → SIGABRT/SIGSEGV
Reproducer:
class It:
def __iter__(self): return self
def __next__(self): return 1
def throw(self, typ, val=None, tb=None):
e = StopIteration(99)
del e.value
raise e
def outer():
yield from It()
g = outer()
next(g)
g.throw(ValueError) # Segmentation fault (core dumped)
Both confirmed on main at 5a22a62b96a.
Root cause — exceptions.c:721 declares value as _Py_T_OBJECT with
flags=0, which permits del. Fix: use _Py_T_OBJECT_EX or add Py_READONLY,
or add NULL guards in both consumers.
Found while auditing CPython with a static-analysis toolkit flagging Py_NewRef/Py_XNewRef mismatches.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Output from running 'python -VV' on the command line:
Python 3.16.0a0 (heads/main:1a852139408, Oct 3 2026, 10:47:03) [GCC 13.3.0]
--
Found this while auditing CPython using cpython-review-toolkit (maintained by @devdanzin and myself).
Crash report
del e.valueon aStopIterationinstance stores NULL intoPyStopIterationObject.value. The getter substitutesPy_Noneso itlooks fine at Python level, but two C consumers dereference it unconditionally.
Consumer 1 —
genobject.c:818,gen_send_ex2:Reproducer:
Consumer 2 —
bytecodes.c:1971,CLEANUP_THROW:Reproducer:
Both confirmed on main at
5a22a62b96a.Root cause —
exceptions.c:721declaresvalueas_Py_T_OBJECTwithflags=0, which permitsdel. Fix: use_Py_T_OBJECT_EXor addPy_READONLY,or add NULL guards in both consumers.
Found while auditing CPython with a static-analysis toolkit flagging
Py_NewRef/Py_XNewRefmismatches.CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Output from running 'python -VV' on the command line:
Python 3.16.0a0 (heads/main:1a852139408, Oct 3 2026, 10:47:03) [GCC 13.3.0]
--
Found this while auditing CPython using cpython-review-toolkit (maintained by @devdanzin and myself).