Sitelet https://github.com/python/cpython/issues/140332
Skip to content

MemorySanitizer: use-of-uninitialized-value in _ssl.txt2obj via OpenSSL's OBJ_txt2obj #140332

Description

@ashm-dev

Bug report

Bug Description

When CPython is built with MemorySanitizer (MSAN), the build fails during module initialization with a use-of-uninitialized-value error in memcmp during the call to OpenSSL's OBJ_txt2obj() function.

How to Reproduce

Build CPython with MSAN:

CC=clang CXX=clang++ ./configure --disable-optimizations --with-pydebug --with-memory-sanitizer --enable-experimental-jit=yes && make -j$(nproc)

The error occurs automatically during the build process when importing modules.

Expected Behavior

The build should complete successfully without memory sanitizer warnings.

Actual Behavior

MemorySanitizer reports:

Uninitialized bytes in MemcmpInterceptorCommon at offset 0 inside [0x701000000032, 8)
==808699==WARNING: MemorySanitizer: use-of-uninitialized-value
    #0 memcmp
    #1 libcrypto.so.3 (OBJ_bsearch_ex_)
    #2 libcrypto.so.3 (OBJ_obj2nid)
    #3 libcrypto.so.3 (d2i_ASN1_OBJECT)
    #4 libcrypto.so.3 (OBJ_txt2obj)
    #5 _ssl_txt2obj_impl /root/cpython/main/./Modules/_ssl.c:6396:11

Build fails with:

make: *** [Makefile:1767: checksharedmods] Error 1

Full stack trace attached in comments.

Environment

  • OpenSSL: 3.5.1 (system installation)

Additional Context

This blocks building CPython with MemorySanitizer enabled.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Activity

  1. StanFromIreland commented on Oct 19, 2025

    @StanFromIreland
    Member

    This is an issue in a third-party library, and the linked issue openssl/openssl#17784 was closed as the OpenSSL team decided this was a false positive?

    cc @vstinner

  2. thesamesam commented on Oct 19, 2025

    @thesamesam
    Contributor

    System OpenSSL needs to be built with -fsanitize=memory for proper MSAN compatibility

    All linked libraries must indeed be built with MSAN.

  3. picnixz commented on Oct 19, 2025

    @picnixz
    Member

    Also if you want a full coverage of ssl + hashlib modules, you need to build both OpenSSL 3.5 and OpenSSL 1.1.1 from sources with M/ASan because some code paths are conditioned to the OpenSSL version.

    More generally, linked librairies must he built with the corresponding sanitizers (so this includes at least ncurses and openssl for CPython, as well as all the compression libs which I do not remember the name of)

  4. vstinner commented on Oct 28, 2025

    @vstinner
    Member

    This is an issue in a third-party library, and the linked issue openssl/openssl#17784 was closed as the OpenSSL team decided this was a false positive?

    It was closed because OpenSSL was not built with MSAN. So yes, it's a false positive.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    buildThe build process and cross-buildextension-modulesC modules in the Modules dirpendingThe issue will be closed if no feedback is providedtopic-SSLtype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions