Skip to content

gh-91087: Reject negative local file header offsets in zipfile - #158913

Open
emerardd wants to merge 1 commit into
python:mainfrom
emerardd:fix/gh-91087-negative-header-offset
Open

emerardd wants to merge 1 commit into
python:mainfrom
emerardd:fix/gh-91087-negative-header-offset

Conversation

@emerardd

@emerardd emerardd commented Oct 6, 2026 •

Copy link
Copy Markdown

Removing bytes before a ZIP archive's central directory can leave a member with a negative local file header offset. Reading that member currently raises OSError for a real file or ValueError for BytesIO, so ZipFile.testzip() propagates the seek error instead of reporting the corrupt member.

Check the offset in ZipFile.open() before creating the shared file reader and raise BadZipFile. This lets testzip() return the affected member's name while allowing intact members to be read. Genuine I/O errors continue to propagate.

The regression tests cover filenames, temporary files, and BytesIO, both member names and ZipInfo arguments, and reading an intact member from the same damaged archive. A separate test checks that seek failures on a valid archive are not swallowed.

Validation on a locally built Windows x64 debug CPython 3.16.0a0:

  • The new corruption test fails on the original implementation for all three input types.
  • Both new tests pass with the fix.
  • python_d.exe -m test -v test_zipfile: 603 tests run, 5 skipped, success.
  • Ruff 0.15.17 checks and git diff --check pass.

Linux and macOS validation has not been run locally.

Fixes #91087.

@python-cla-bot

python-cla-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.

CLA signed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

zipfile library will raise uncaught oserror when reading length incorrect zip file

1 participant