Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[3.9] gh-98517: Fix buffer overflows in _sha3 module (GH-98519) #98526

Merged
merged 1 commit into from Oct 28, 2022

Conversation

miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Oct 21, 2022

This is a port of the applicable part of XKCP's fix 1 for
CVE-2022-37454 and avoids the segmentation fault and the infinite
loop in the test cases published in 2.

Regression test added by: Gregory P. Smith [Google LLC] greg@krypto.org
(cherry picked from commit 0e4e058)

Co-authored-by: Theo Buehler botovq@users.noreply.github.com

…-98519)

This is a port of the applicable part of XKCP's fix [1] for
CVE-2022-37454 and avoids the segmentation fault and the infinite
loop in the test cases published in [2].

[1]: XKCP/XKCP@fdc6fef
[2]: https://mouha.be/sha-3-buffer-overflow/

Regression test added by: Gregory P. Smith [Google LLC] <greg@krypto.org>
(cherry picked from commit 0e4e058)

Co-authored-by: Theo Buehler <botovq@users.noreply.github.com>
@miss-islington miss-islington requested a review from tiran as a code owner Oct 21, 2022
@bedevere-bot bedevere-bot added type-crash A hard crash of the interpreter, possibly with a core dump type-security A security issue labels Oct 21, 2022
@gpshead gpshead changed the title [3.9] [3.10] gh-98517: Fix buffer overflows in _sha3 module (GH-98519) [3.9] gh-98517: Fix buffer overflows in _sha3 module (GH-98519) Oct 21, 2022
@gpshead gpshead added the 3.9 label Oct 21, 2022
@miss-islington
Copy link
Contributor Author

miss-islington commented Oct 21, 2022

Sorry, I can't merge this PR. Reason: You're not authorized to push to this branch. Visit https://docs.github.com/articles/about-protected-branches/ for more information..

@ambv ambv merged commit 857efee into python:3.9 Oct 28, 2022
16 checks passed
@miss-islington miss-islington deleted the backport-0e4e058-3.9 branch Oct 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.9 release-blocker type-crash A hard crash of the interpreter, possibly with a core dump type-security A security issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants