Skip to content

fix(datasets): reject link and traversal members before tar extraction - #9593

Open
erensh27 wants to merge 1 commit into
pytorch:mainfrom
erensh27:fix/tar-extraction-path-traversal
Open

fix(datasets): reject link and traversal members before tar extraction#9593
erensh27 wants to merge 1 commit into
pytorch:mainfrom
erensh27:fix/tar-extraction-path-traversal

Conversation

@erensh27

@erensh27 erensh27 commented Aug 9, 2026

Copy link
Copy Markdown

Security fix for #9517: extract_archive / download_and_extract_archive exposed untrusted tar archives to tar.extractall, which follows symlink/hardlink members and allows .. traversal to escape the destination.

torchvision/datasets/utils.py_extract_tar now validates every member before extraction and raises RuntimeError for:

  • symlink, hardlink, or device members
  • members with absolute paths
  • members containing a .. segment

The safe-subset validation mirrors tarfile.data_filter (PEP 706) but remains portable to all supported Python versions. zip.extractall is left unchanged: zipfile has built-in traversal sanitization on all supported Pythons.

Teststest/test_datasets_utils.py: crafted archives with a symlink member, a ../escape.txt member, and a /absolute.txt member are rejected, and nothing is written outside the destination. Logged-can't-run note: tests require a full torch env; the test module compiles.

tar.extractall() follows symlink/hardlink members and honors '..'
segments, so a malicious archive extracted via download_and_extract_
archive() / extract_archive() could write outside the destination
directory (see pytorch#9517).

_extract_tar now rejects, before extracting, any member that is a
symlink, hardlink, or device file, has an absolute path, or contains a
'..' segment. The safe-subset validation mirrors tarfile.data_filter
(PEP 706) but stays portable across supported Python versions.

Adds regression tests for link, traversal, and absolute-path members.
@pytorch-bot

pytorch-bot Bot commented Aug 9, 2026

Copy link
Copy Markdown

🔗 Helpful Links

🧪 See artifacts and rendered test results at hud.pytorch.org/pr/pytorch/vision/9593

Note: Links to docs will display an error until the docs builds have been completed.

This comment was automatically generated by Dr. CI and updates every 15 minutes.

@meta-cla

meta-cla Bot commented Aug 9, 2026

Copy link
Copy Markdown

Hi @erensh27!

Thank you for your pull request and welcome to our community.

Action Required

In order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you.

Process

In order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA.

Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with CLA signed. The tagging process may take up to 1 hour after signing. Please give it that time before contacting us about it.

If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks!

@meta-cla meta-cla Bot added the cla signed label Aug 10, 2026
@meta-cla

meta-cla Bot commented Aug 10, 2026

Copy link
Copy Markdown

Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant