in scan_once, prevent the reading of arbitrary memory when passed a negative index
Bug reported by Guido Vranken.
diff --git a/Misc/ACKS b/Misc/ACKS
index b950474..a932074 100644
--- a/Misc/ACKS
+++ b/Misc/ACKS
@@ -1139,6 +1139,7 @@
Johannes Vogel
Martijn Vries
Sjoerd de Vries
+Guido Vranken
Niki W. Waibel
Wojtek Walczak
Charles Waldman
diff --git a/Misc/NEWS b/Misc/NEWS
index 3913f94..e44219a 100644
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -10,6 +10,9 @@
Library
-------
+- Fix arbitrary memory access in JSONDecoder.raw_decode with a negative second
+ parameter. Bug reported by Guido Vranken.
+
- Issue #21082: In os.makedirs, do not set the process-wide umask. Note this
changes behavior of makedirs when exist_ok=True.