FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

gh-91087: Reject negative local file header offsets in zipfile by emerardd · Pull Request #158913 · python/cpython · GitHub

Repository navigation

gh-91087: Reject negative local file header offsets in zipfile - #158913

Open
emerardd wants to merge 1 commit into
python:mainfrom
emerardd:fix/gh-91087-negative-header-offset
Open

emerardd wants to merge 1 commit into
python:mainfrom
emerardd:fix/gh-91087-negative-header-offset

Conversation

emerardd commented Oct 6, 2026 •
edited by bedevere-app Bot
Loading

Copy link
Copy Markdown

Removing bytes before a ZIP archive's central directory can leave a member with a negative local file header offset. Reading that member currently raises OSError for a real file or ValueError for BytesIO, so ZipFile.testzip() propagates the seek error instead of reporting the corrupt member.

Check the offset in ZipFile.open() before creating the shared file reader and raise BadZipFile. This lets testzip() return the affected member's name while allowing intact members to be read. Genuine I/O errors continue to propagate.

The regression tests cover filenames, temporary files, and BytesIO, both member names and ZipInfo arguments, and reading an intact member from the same damaged archive. A separate test checks that seek failures on a valid archive are not swallowed.

Validation on a locally built Windows x64 debug CPython 3.16.0a0:

  • The new corruption test fails on the original implementation for all three input types.
  • Both new tests pass with the fix.
  • python_d.exe -m test -v test_zipfile: 603 tests run, 5 skipped, success.
  • Ruff 0.15.17 checks and git diff --check pass.

Linux and macOS validation has not been run locally.

Fixes #91087.

python-cla-bot Bot commented Oct 6, 2026 •
edited
Loading

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

zipfile library will raise uncaught oserror when reading length incorrect zip file

1 participant


Back | FazBrowse Home | New Git URL