Skip to content

Stored ZIP entries can report successful completion despite truncated data #134496

Description

@alinpahontu2912

For stored ZIP entries, the archive metadata can declare a compressed size that is smaller than the entry's uncompressed size. In this scenario, the reader may reach EOF before consuming the expected amount of data and still report successful completion.
This behavior is inconsistent with the documented completed-read validation contract. A fully drained entry read can succeed even though the entry data is truncated and CRC validation is never performed.

Activity

  1. dotnet-policy-service commented on Sep 23, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @karelz, @dotnet/area-system-io-compression
    See info in area-owners.md if you want to be subscribed.

  2. added a commit that references this issue on Sep 25, 2026
    581440b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions