#1142473 python-pyzipper: CVE-2026-44722

Package:
src:python-pyzipper
Source:
src:python-pyzipper
Submitter:
Salvatore Bonaccorso
Date:
2026-09-07 16:07:05 UTC
Severity:
normal
Tags:
#1142473#5
Date:
2026-07-20 12:18:34 UTC
From:
To:
Hi,

The following vulnerability was published for python-pyzipper.

CVE-2026-44722[0]:
| pyzipper is a replacement for Python's zipfile that can read and
| write AES encrypted zip files. Prior to 0.4.0, a Python operator
| precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to
| never be automatically selected during encryption, causing encrypted
| entries to be written in AE-1 format and exposing the plaintext
| CRC32 checksum in the ZIP header and, for unseekable zip archives,
| in the datadescripter section, allowing an attacker who possesses
| the archive to brute-force candidate plaintexts for small or low-
| entropy files by comparing CRC32 values. This issue is fixed in
| version 0.4.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-44722
https://www.cve.org/CVERecord?id=CVE-2026-44722
[1] https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
[2] https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae

Regards,
Salvatore

#1142473#10
Date:
2026-09-07 16:04:48 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-pyzipper, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142473@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <cjwatson@debian.org> (supplier of updated python-pyzipper package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 07 Sep 2026 16:29:27 +0100
Source: python-pyzipper
Architecture: source
Version: 0.4.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Closes: 1142473
Changes:
 python-pyzipper (0.4.0-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release:
     - CVE-2026-44722: Fix bug where CRC32 values were not removed for small
       files.  pyzipper no longer writes any CRC32 values by default,
       regardless of file size.  The CRC32 value could be used to brute-force
       candidate plaintexts by computing CRC32(candidate) and comparing
       against the stored value.  In practice, this attack is feasible today
       only against small or low-entropy files, as CRC32 exhaustion across a
       large plaintext space is computationally prohibitive on current
       hardware (closes: #1142473).
   * Drop python-pyzipper-doc package; upstream no longer ships Sphinx
     documentation.
   * Drop "Rules-Requires-Root: no", default as of dpkg-dev 1.22.13.
   * Drop "Priority: optional", default as of dpkg-dev 1.22.13.
   * Standards-Version: 4.7.4.
Checksums-Sha1:
 982a24e6c93e5c5ea4bc2394155b7b958bdeaf1c 2649 python-pyzipper_0.4.0-1.dsc
 b53b3a05f769bf975bd765f831ed0e7891cda13b 136213 python-pyzipper_0.4.0.orig.tar.gz
 a8d18bae67a759a99f97ee2af697bdeac927268f 5348 python-pyzipper_0.4.0-1.debian.tar.xz
 599622841b5febe50890691b48e0a642516f1993 294880 python-pyzipper_0.4.0-1.git.tar.xz
 3a9eff8e6da528f078143f10fa1a9297d850759f 17700 python-pyzipper_0.4.0-1_source.buildinfo
Checksums-Sha256:
 a0cc9d5314a80eef5c6932b85daf8626d0785a8f31a6138135b32ea928665340 2649 python-pyzipper_0.4.0-1.dsc
 2b61fb9c5d19e0222ab9d5adbf6ff7f036a64ed26128a7d2bdc1acc45a153be4 136213 python-pyzipper_0.4.0.orig.tar.gz
 1507f66f0b3951c617fbdc084232609346f1f177754a3027f5d61a401fed16aa 5348 python-pyzipper_0.4.0-1.debian.tar.xz
 a40c334cd0f4ae54e1c33e86562824e59ec4850d9158e4c0b757a4bc5131bbd0 294880 python-pyzipper_0.4.0-1.git.tar.xz
 34dcbac45238622f63a5fa216c8d56afd038e692df0ecd7f8de1fbe2872b36ad 17700 python-pyzipper_0.4.0-1_source.buildinfo
Files:
 c44895101c31458a1aece04fef85e276 2649 python optional python-pyzipper_0.4.0-1.dsc
 b86e1e76ae91cdeb6d90b34ee2e0e081 136213 python optional python-pyzipper_0.4.0.orig.tar.gz
 634e8bae290fdaa957fb3585a6413428 5348 python optional python-pyzipper_0.4.0-1.debian.tar.xz
 dc9fcb0b23abdf6af5f9487ada7c98ea 294880 python None python-pyzipper_0.4.0-1.git.tar.xz
 91c4fa6287032a21210b8d50a16a032c 17700 python optional python-pyzipper_0.4.0-1_source.buildinfo
Git-Tag-Info: tag=73a6abbc3808abbba10b56ae298d03c46b54c1d2 fp=ac0a4ff12611b6fccf01c111393587d97d86500b
Git-Tag-Tagger: Colin Watson <cjwatson@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqe2qwACgkQYG0ITkaD
wHn7HhAAr6GQtvIqsMgbiIwKw9ForwA5IoDKLvSftk6N2Am7MavnUjbj3qG4HkYd
PvS1r98+VniKld9mbGsv0Gcf21uDfQ429paneZilOn+jCip+e1LF6UsFL1QLCAWt
FyC4/ZQ0k3ZZS60ZgMYFr6lilJqklgtOuA/ovBrsH8nUFnVawryf6GvUeY++rKAi
AN4YPr6gs+RHS5tCqpyxr5Oe/u64OylGeEBjDmpGgd9As6H0KKHuXv5K/yYIF+n4
ChHkzIColbPZDrnAd7VjOxymb75A2Km0FXUQZXDgofI5MnJAPQyY/FM5QCafYAe2
Em9/r7K1sB7mcDfA+Brqjp239tTUZuIgGd+UOe7sAjqbjtTSk5txmpRiJ+zE/gdN
6ANWD3Uk43JeAf6pr14Wamctv47MoHpZTWk96qy4Wcmqk2Ls0hDFMwFrytxu/2qE
6klpXmQV+zYTnsgz+jWuCIwtU0oK0YzZpOiX9pcMzuPOw81i0Gp4aX6voYFFkv5Y
Injt/UpiaC0vNWk6laZbh1v5G0TVShHUnYghpN/SciKrkxcyv8Kq5pfw6RX0KDak
ATMporuQFplcNzNfz4U29p2ll5bLiYhkczMSlp9bXWG9JOg7ctShD67bfCOWtxAO
8WfXd35IMSYrpewimAZENR3pk2nRys2lT9BSt91cbdOa2F2tm90=
=Uiz4
-----END PGP SIGNATURE-----