getpath_isxfile() in Modules/getpath.c frees the path buffer before the last use:
DWORD attr = GetFileAttributesW(path);
PyMem_Free(path);
isxfile = (attr != INVALID_FILE_ATTRIBUTES) &&
!(attr & FILE_ATTRIBUTE_DIRECTORY) &&
(cchPath >= 4) &&
(CompareStringOrdinal(path + cchPath - 4, -1, L".exe", -1, 1 /* ignore case */) == CSTR_EQUAL);
CompareStringOrdinal() reads path + cchPath - 4 after PyMem_Free(path), so the result of the .exe check depends on freed memory. The function is called during interpreter startup, when looking for the executable.
Only the main branch is affected: the early free was introduced in GH-153230, before which the buffer was freed at the end of the block.
getpath_isxfile()inModules/getpath.cfrees the path buffer before the last use:CompareStringOrdinal()readspath + cchPath - 4afterPyMem_Free(path), so the result of the.execheck depends on freed memory. The function is called during interpreter startup, when looking for the executable.Only the main branch is affected: the early free was introduced in GH-153230, before which the buffer was freed at the end of the block.