Skip to content

22 free-threading race conditions #149816

Description

@lunixbochs

Bug report

Changes

2026-05-13: Filed issue.
2026-06-08: Added new findings (16) and (86).

Bug description

I found 22 free-threading race conditions during a partial Xint Code scan of cpython. These only apply to the free-threaded build, and were all found and tested on commit 0534774 built with ./configure --disable-gil --enable-asan on an M3 Mac.

I'm attaching a zip file with detailed writeups of each, as well as reproduction cases for 15 of the 22 issues. I don't have scripts reproducing the findings numbered 21, 36, 82, 94, 106, 115, or 124. Race conditions can be difficult to trigger, and even the scripts I provided are trying to win tight races and may not always work.

I know this is a lot. @colesbury suggested I create a combined issue to make the triage discussion easier.

Let me know if you have any questions or concerns. The issues were found and written up by an automated system, but I have put additional work into the validation and reporting. I do want to be respectful of everyone's time while helping to make Python better.

Writeups

2026-05-13: Initial writeups and test scripts: cpython-ft.zip
2026-06-08: New writeups and test scripts for (16) and (86): cpython-ft-2026-06-08.zip

Many of the scripts are expected to crash, however some of them only produce exceptions or corrupted output. You should be able to run any of the scripts with PYTHON_GIL=1 set in your environment if you want to see a baseline without the race condition.

Finding List

  • (16) Cross-interpreter syslog race
  • (17) Unlocked __init__ races with PRNG state access in Modules/_randommodule.c
  • (21) Racy EVP_MD cache overwrite leaks references in Modules/_hashopenssl.c
  • (36) Borrowed type lookup races to use-after-free in Objects/typeobject.c
  • (49) SNI callback callable race use-after-free in Modules/_ssl.c
  • (61) Racy weakref head load before incref in Objects/typeobject.c
  • (62) Concurrent kwargs growth causes heap overwrite in Objects/call.c
  • (69) Unsynchronized extra pointer dereference in len in Modules/_elementtree.c
  • (82) Non-atomic list slot memmove in shared list delete in Objects/listobject.c
  • (84) Iterator path bypasses buffered object lock in Modules/_io/bufferedio.c
  • (86) Cross-interpreter XID registry race
  • (87) Unsynchronized Element.text borrowed-pointer race in Modules/_elementtree.c
  • (89) Unsynchronized dict iteration causes borrowed-ref UAF in Modules/_pickle.c
  • (91) Racy list item borrow causes UAF in Modules/_pickle.c
  • (94) Async-exception setter races thread-state free in Python/pystate.c
  • (96) Racy GC callback list iteration in Python/gc_free_threading.c
  • (106) Immediate decref races lock-free reader in Modules/_ctypes/_ctypes.c
  • (108) Borrowed dict used after lock release in Objects/dictobject.c
  • (115) Split clear frees keys without QSBR in Objects/dictobject.c
  • (124) Stale keys race in attribute hint fastpath in Python/bytecodes.c
  • (125 wontfix) Struct reinit races with pack/unpack in Modules/_struct.c
  • (128) Borrowed list item raced before incref in Objects/bytesobject.c
  • (129) Reentrant __index__ causes released-buffer dereference in Objects/memoryobject.c
  • (132) Non-atomic exports race in memoryview.hex in Objects/memoryobject.c

CPython versions tested on:

3.14

Operating systems tested on:

macOS

Linked PRs

Activity

  1. skirpichev commented on May 14, 2026

    @skirpichev
    Member

    (125) Struct reinit races with pack/unpack in Modules/_struct.c

    Is this is same as #143379?

  2. lunixbochs commented on May 14, 2026

    @lunixbochs
    ContributorAuthor

    (125) Struct reinit races with pack/unpack in Modules/_struct.c

    Is this is same as #143379?

    Looks pretty similar, just as a threading race instead of reentrancy.

  3. skirpichev commented on May 14, 2026

    @skirpichev
    Member

    Then I think it's not something worth fixing, on same ground.

  4. added a commit that references this issue on May 14, 2026
  5. kumaraditya303 commented on May 14, 2026

    @kumaraditya303
    Contributor

    I don't think it is worth fixing issues of calling __init__ in multiple threads.

  6. lunixbochs commented on May 14, 2026

    @lunixbochs
    ContributorAuthor

    Neither of the mentioned init bugs (struct / random) are init racing with itself, they're init racing with something else. The struct bug is far more contrived because it requires you to call init a second time while using the struct object. The random init/sample race seems fine to fix because if someone ever does manage to hit that they won't even get a crash, just incorrect numbers out of their seeded rng.

    There's a separate question on the cpython philosophy of "should a script be able to intentionally crash or memory corrupt the interpreter using the stdlib and no ctypes?", which should inform whether more contrived reentrancy issues / race conditions should be fixed

  7. picnixz commented on May 15, 2026

    @picnixz
    Member

    I will have a look at all issues related to SSL and crypto myself in 10 days unless someone beats me to it.

  8. added 4 commits that reference this issue on May 15, 2026
  9. sobolevn commented on May 16, 2026

    @sobolevn
    Member

    (36) does not seem correct, because _PyType_Lookup is supposed to return the borrowed reference by design.

  10. 44 remaining items

  11. lunixbochs commented on Jun 8, 2026

    @lunixbochs
    ContributorAuthor

    I added two cross-interpreter free-threading races to the list (16) and (86), and attached another zip to the issue description with their writeups and reproduction scripts:

    • (16) Cross-interpreter syslog race: syslog.syslog() borrows a global without a cross-interpreter lock.
    • (86) Cross-interpreter XID registry race: the local XID registry relies on GIL acquisition for thread safety, which doesn't work in free-threaded builds.
  12. added a commit that references this issue on Jun 8, 2026
  13. IvyXu420 commented on Jun 10, 2026

    @IvyXu420
    Contributor

    #149918 fixes (69) Unsynchronized extra pointer dereference in len in Modules/_elementtree.c. Would any core dev like to review it? Thanks in advance!

  14. Abhi210 commented on Jun 25, 2026

    @Abhi210
    Contributor

    @lunixbochs I am unable to reproduce the issue (124) Stale keys race in attribute hint fastpath in Python/bytecodes.c. Do you have a specific reproduction script or build configuration (ASAN flags, usleep placement, specific interleaving) that reliably surfaces #124 as a sanitizer report or assertion failure? Or is the intent that the issue is demonstrated purely through code-path analysis rather than a live crash/sanitizer report?

  15. added a commit that references this issue on Jun 29, 2026
  16. added 2 commits that reference this issue on Jul 4, 2026
  17. added a commit that references this issue on Jul 12, 2026
  18. added a commit that references this issue on Jul 15, 2026
  19. added a commit that references this issue on Jul 17, 2026
  20. added 2 commits that reference this issue on Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions