CVE-2025-8291
published 2025-10-07CVE-2025-8291: The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.35%
27.5th percentile
The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jython | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | pypy3 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.11 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.13 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.14 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| msrc | azl3_python3_3.12.9-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python3_3.9.19-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-16_on_cbl_mariner_2.0 | — | — |
| python_software_foundation | cpython | < 3.10.19 | 3.10.19 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.14 | 3.11.14 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.12 | 3.12.12 |
| python_software_foundation | cpython | >= 3.13.0 < 3.13.10 | 3.13.10 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.1 | 3.14.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-11-26·CVSS 5.5
CVE-2025-6075 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-7886-1 fixed vulnerabilities in Python. This update provides the
corresponding updates for python3.13 in Ubuntu 25.04 and Ubuntu 25.10.
Original advisory details:
It was discovered that Python inefficiently handled expanding system
environment variables. An attacker could possibly use this issue to cause
Python to consume excessive resources, leading to a denial of service.
(CVE-2025-6075)
Caleb Brown discovered that Python incorrectly handled the ZIP64 End of
Central Directory (EOCD) Locator record offset value. An attacker could
possibly use this issue to obfuscate malicious content. (CVE-2025-8291)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-11-24·CVSS 5.5
CVE-2025-6075 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python inefficiently handled expanding system
environment variables. An attacker could possibly use this issue to cause
Python to consume excessive resources, leading to a denial of service.
(CVE-2025-6075)
Caleb Brown discovered that Python incorrectly handled the ZIP64 End of
Central Directory (EOCD) Locator record offset value. An attacker could
possibly use this issue to obfuscate malicious content. (CVE-2025-8291)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
ZIP64 End of Central Directory (EOCD) Locator record offset not checked
vendor_msrc·2025-10-14·CVSS 4.3
CVE-2025-8291 [MEDIUM] ZIP64 End of Central Directory (EOCD) Locator record offset not checked
ZIP64 End of Central Directory (EOCD) Locator record offset not checked
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: h
Red Hat
cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
vendor_redhat·2025-10-07·CVSS 4.3
CVE-2025-8291 [MEDIUM] CWE-130 cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.
A zip file handling flaw has been discovered in the python standard library `zipfile` module. The 'zipfile' module would not check the validity of the ZIP64 End o
Debian
CVE-2025-8291: jython - The 'zipfile' module would not check the validity of the ZIP64 End of Central Di...
vendor_debian·2025·CVSS 4.3
CVE-2025-8291 [MEDIUM] CVE-2025-8291: jython - The 'zipfile' module would not check the validity of the ZIP64 End of Central Di...
The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
python3.13 vulnerabilities
osv·2025-11-26·CVSS 1.8
CVE-2025-6075 [LOW] python3.13 vulnerabilities
python3.13 vulnerabilities
USN-7886-1 fixed vulnerabilities in Python. This update provides the
corresponding updates for python3.13 in Ubuntu 25.04 and Ubuntu 25.10.
Original advisory details:
It was discovered that Python inefficiently handled expanding system
environment variables. An attacker could possibly use this issue to cause
Python to consume excessive resources, leading to a denial of service.
(CVE-2025-6075)
Caleb Brown discovered that Python incorrectly handled the ZIP64 End of
Central Directory (EOCD) Locator record offset value. An attacker could
possibly use this issue to obfuscate malicious content. (CVE-2025-8291)
OSV
python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
osv·2025-11-24·CVSS 1.8
CVE-2025-6075 [LOW] python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
It was discovered that Python inefficiently handled expanding system
environment variables. An attacker could possibly use this issue to cause
Python to consume excessive resources, leading to a denial of service.
(CVE-2025-6075)
Caleb Brown discovered that Python incorrectly handled the ZIP64 End of
Central Directory (EOCD) Locator record offset value. An attacker could
possibly use this issue to obfuscate malicious content. (CVE-2025-8291)
OSV
CVE-2025-8291: The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate
osv·2025-10-07·CVSS 4.3
CVE-2025-8291 [MEDIUM] CVE-2025-8291: The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate
The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.
GHSA
GHSA-49g5-f6qw-8mm7: The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate
ghsa_unreviewed·2025-10-07
CVE-2025-8291 [MEDIUM] CWE-1285 GHSA-49g5-f6qw-8mm7: The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate
The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8291 python3.6: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
bugzilla·2025-10-09·CVSS 4.3
CVE-2025-8291 [MEDIUM] CVE-2025-8291 python3.6: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
CVE-2025-8291 python3.6: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
We are not going to fix this if it's unfixed in RHEL 8.
---
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining an
Bugzilla
CVE-2025-8291 asahi-installer: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
bugzilla·2025-10-09·CVSS 4.3
CVE-2025-8291 [MEDIUM] CVE-2025-8291 asahi-installer: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
CVE-2025-8291 asahi-installer: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It
Bugzilla
CVE-2025-8291 cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
bugzilla·2025-10-07·CVSS 4.3
CVE-2025-8291 [MEDIUM] CVE-2025-8291 cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
CVE-2025-8291 cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked
The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:23530 https://access.redhat.com/e
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
blogs_bleepingcomputer·2025-10-14·CVSS 7.8
[HIGH] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Lawrence Abrams
80 Elevation of Privilege Vulnerabilities
11 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
28 Information Disclosure Vulnerabilities
11 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include those fixed in Azure, Mariner, Microsoft Edge, and other vulnerabilities earlier this month.
Notably, Windows 10 reaches the end of support today , with this being the last Patch Tuesday where Microsoft provides free security updates to the venerable operating system.
To continue receiving security upd
https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3https://github.com/python/cpython/issues/139700https://github.com/python/cpython/pull/139702https://mail.python.org/archives/list/[email protected]/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6phttps://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json
2025-10-07
Published