gh-156002: Bound zipfile decompression for bzip2/LZMA/Zstandard (GH-156003)
Patch by @tonghuaroot. zipfile.ZipExtFile._read1() bounds the output of each decompress() call for DEFLATE members by passing a max_length to zlib, but for bzip2, LZMA, and Zstandard members it called decompress() with no bound. A whole compressed chunk was therefore expanded into a single allocation before the data[:self._left] clip ran, so a consumer that deliberately reads in small chunks to limit memory (for example zf.open(name).read(8192)) was silently unprotected for non-DEFLATE members. A small, spec-conformant archive member declaring a large uncompressed size could drive multi-GB peak memory. _read1() now passes a per-call bound to the non-DEFLATE decompress() (mirroring the DEFLATE branch) and drains the decompressor's internal buffer across calls by checking needs_input before reading more compressed input. zipfile's LZMADecompressor wrapper forwards max_length and exposes needs_input so the bound also holds for LZMA members. Co-authored-by: tonghuaroot <tonghuaroot@gmail.com>
P
Petr Viktorin committed
f897dbf2f36a5935700b7c2d94d4681d2136b7d4
Parent: 9cbd578
Committed by GitHub <noreply@github.com>
on 8/24/2026, 11:34:41 AM