diff --git a/src/libraries/System.Private.CoreLib/src/Resources/Strings.resx b/src/libraries/System.Private.CoreLib/src/Resources/Strings.resx
index e7dc54f16d1940..bbf9c3f213d980 100644
--- a/src/libraries/System.Private.CoreLib/src/Resources/Strings.resx
+++ b/src/libraries/System.Private.CoreLib/src/Resources/Strings.resx
@@ -2606,6 +2606,9 @@
Common Language Runtime detected an invalid program.
+
+ The time zone ID '{0}' is invalid.
+
The time zone ID '{0}' was found on the local computer, but the file at '{1}' was corrupt.
@@ -2630,6 +2633,9 @@
This assembly does not have a file table because it was loaded from memory.
+
+ Unsupported unseekable file.
+
Unable to read beyond the end of the stream.
diff --git a/src/libraries/System.Private.CoreLib/src/System/TimeZoneInfo.Unix.NonAndroid.cs b/src/libraries/System.Private.CoreLib/src/System/TimeZoneInfo.Unix.NonAndroid.cs
index 45eb47885ba812..f90b52bdc52053 100644
--- a/src/libraries/System.Private.CoreLib/src/System/TimeZoneInfo.Unix.NonAndroid.cs
+++ b/src/libraries/System.Private.CoreLib/src/System/TimeZoneInfo.Unix.NonAndroid.cs
@@ -29,11 +29,55 @@ private static TimeZoneInfo GetLocalTimeZoneCore()
return GetLocalTimeZoneFromTzFile();
}
+ private static byte[] ReadAllBytesFromSeekableNonZeroSizeFile(string path, int maxFileSize)
+ {
+ using FileStream fs = File.OpenRead(path);
+ if (!fs.CanSeek)
+ {
+ throw new IOException(SR.IO_UnseekableFile);
+ }
+
+ if (fs.Length == 0 || fs.Length > maxFileSize)
+ {
+ throw new IOException(fs.Length == 0 ? SR.IO_InvalidReadLength : SR.IO_FileTooLong);
+ }
+
+ byte[] bytes = new byte[fs.Length];
+ fs.ReadExactly(bytes, 0, bytes.Length);
+ return bytes;
+ }
+
+ // Bitmap covering the ASCII range. The bits is set for the characters [a-z], [A-Z], [0-9], '/', '-', and '_'.
+ private static byte[] asciiBitmap = new byte[] { 0x00, 0x00, 0x00, 0x00, 0x00, 0xA8, 0xFF, 0x03, 0xFE, 0xFF, 0xFF, 0x87, 0xFE, 0xFF, 0xFF, 0x07 };
+ private static bool IdContainsAnyDisallowedChars(string zoneId)
+ {
+ for (int i = 0; i < zoneId.Length; i++)
+ {
+ int c = zoneId[i];
+ if (c > 0x7F)
+ {
+ return true;
+ }
+ int value = c >> 3;
+ if ((asciiBitmap[value] & (ulong)(1UL << (c - (value << 3)))) == 0)
+ {
+ return true;
+ }
+ }
+ return false;
+ }
+
private static TimeZoneInfoResult TryGetTimeZoneFromLocalMachineCore(string id, out TimeZoneInfo? value, out Exception? e)
{
value = null;
e = null;
+ if (Path.IsPathRooted(id) || IdContainsAnyDisallowedChars(id))
+ {
+ e = new TimeZoneNotFoundException(SR.Format(SR.InvalidTimeZone_InvalidId, id));
+ return TimeZoneInfoResult.TimeZoneNotFoundException;
+ }
+
byte[]? rawData=null;
string timeZoneDirectory = GetTimeZoneDirectory();
string timeZoneFilePath = Path.Combine(timeZoneDirectory, id);
@@ -61,7 +105,7 @@ private static TimeZoneInfoResult TryGetTimeZoneFromLocalMachineCore(string id,
try
{
- rawData = File.ReadAllBytes(timeZoneFilePath);
+ rawData = ReadAllBytesFromSeekableNonZeroSizeFile(timeZoneFilePath, maxFileSize: 20 * 1024 * 1024 /* 20 MB */); // timezone files usually less than 1 MB.
}
catch (UnauthorizedAccessException ex)
{
@@ -78,7 +122,7 @@ private static TimeZoneInfoResult TryGetTimeZoneFromLocalMachineCore(string id,
e = ex;
return TimeZoneInfoResult.TimeZoneNotFoundException;
}
- catch (IOException ex)
+ catch (Exception ex) when (ex is IOException || ex is OutOfMemoryException)
{
e = new InvalidTimeZoneException(SR.Format(SR.InvalidTimeZone_InvalidFileData, id, timeZoneFilePath), ex);
return TimeZoneInfoResult.InvalidTimeZoneException;
diff --git a/src/libraries/System.Runtime/tests/System/TimeZoneInfoTests.cs b/src/libraries/System.Runtime/tests/System/TimeZoneInfoTests.cs
index d941efb83da8da..b2369f5842551b 100644
--- a/src/libraries/System.Runtime/tests/System/TimeZoneInfoTests.cs
+++ b/src/libraries/System.Runtime/tests/System/TimeZoneInfoTests.cs
@@ -2083,6 +2083,11 @@ public static IEnumerable