From 85100c96c06b1dc91e70c68723cab6451229f733 Mon Sep 17 00:00:00 2001 From: Anton Volkov Date: Mon, 31 Aug 2026 16:18:40 +0200 Subject: [PATCH 1/2] Do not decref borrowed module dict reference PyModule_GetDict() returns a borrowed reference. The InitOperators() error path called Py_XDECREF(d) on it, dropping the module dict's refcount one too many. That can free the dict prematurely and lead to a use-after-free. Remove the erroneous decref; only the owned module object m needs releasing on this path. --- mkl_umath/src/ufuncsmodule.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/mkl_umath/src/ufuncsmodule.c b/mkl_umath/src/ufuncsmodule.c index 50dd7790..5863081d 100644 --- a/mkl_umath/src/ufuncsmodule.c +++ b/mkl_umath/src/ufuncsmodule.c @@ -54,7 +54,7 @@ PyMODINIT_FUNC PyInit__ufuncs(void) import_umath(); if (InitOperators(d) < 0) { - Py_XDECREF(d); + /* d is a borrowed reference from PyModule_GetDict; do not decref it. */ Py_XDECREF(m); return NULL; } From f59a8f28d0ebb91332c2734c343ef2ca88f2d1b7 Mon Sep 17 00:00:00 2001 From: Anton Volkov Date: Mon, 31 Aug 2026 21:44:43 +0200 Subject: [PATCH 2/2] Add changelog entry for module dict over-decref fix --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 108c47fa..b9021506 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Changed ### Fixed +* Fixed an over-decref of the borrowed module dictionary reference on the module initialization error path [gh-264](https://github.com/IntelPython/mkl_umath/pull/264) ## [0.5.0] - 2026-08-06