Repository navigation
gzip._GzipReader.read() with sometimes uninitialized variable #137571
Copy link
Copy link
Closed
Labels
3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Aug 8, 2025 - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Aug 8, 2025 Just for clarification, does this cause an actual problem in practice? The fix seems simple enough that it's probably worth doing, but I want to make sure this isn't just from fuzzing the private API.
Reacted by Serhiy Storchaka@ZeroIntensity Nope! Neither. I was reviewing various modules to see how similar are different stream implementations across the
stdlib. Many classes provide streaming. They employ different strategies (some copy, some usememoryviewetc.) but overlap, and I was curious if there's any opportunity to contribute. That's how I found gh-137524 also.- added a commit that references this issue
on May 22, 2026 Thank you for your report @maurycy.
Reacted by Maurycy Pawłowski-Wieroński- added3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixes
on May 22, 2026 - added 3 commits that reference this issue
on May 22, 2026
Metadata
Metadata
Assignees
Labels
3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Projects
- StatusShow more project fieldsDone
Bug report
Bug description:
This one is easy to spot but hard to reproduce:
cpython/Lib/gzip.py
Line 589 in d7dbde8
bufis initialized only whenself._decompressor.needs_input:cpython/Lib/gzip.py
Line 577 in d7dbde8
It exists since gh-95534 (#97664).
I spent a lot of time trying to reproduce this bug using the standard zlib decompressor without any success:
results in:
CPython versions tested on:
CPython main branch
Operating systems tested on:
macOS
Linked PRs
UnboundLocalErroringzip._GzipReader.read()#137572