From 24ddd9c2d6ab61cbce7e68d6de36d4df9bd2c3fb Mon Sep 17 00:00:00 2001 From: Hai Shi Date: Sun, 6 Oct 2019 20:17:18 +0800 Subject: [PATCH] bpo-38383: Fix possible integer overflow in startswith() of bytes and bytearray. (GH-16603) --- Objects/bytes_methods.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Objects/bytes_methods.c b/Objects/bytes_methods.c index 37c5f7dbc8..7d13184205 100644 --- a/Objects/bytes_methods.c +++ b/Objects/bytes_methods.c @@ -743,7 +743,7 @@ tailmatch(const char *str, Py_ssize_t len, PyObject *substr, if (direction < 0) { /* startswith */ - if (start + slen > len) + if (start > len - slen) goto notfound; } else { /* endswith */ -- 2.40.0