Skip to content

Reject BLAKE2b digest lengths that abort the process - #971

Open
shaneraphel wants to merge 1 commit into
pyca:mainfrom
shaneraphel:blake2b-digest-length
Open

shaneraphel wants to merge 1 commit into
pyca:mainfrom
shaneraphel:blake2b-digest-length

Conversation

@shaneraphel

@shaneraphel shaneraphel commented Oct 2, 2026 •

Copy link
Copy Markdown

Fixes #967 and #964.

crypto_generichash_blake2b_final calls sodium_misuse when the output length is 0 or greater than 64, which aborts the interpreter. generichash_blake2b_init and the one-shot helper only rejected lengths above 64, so a length of 0 reached libsodium. A Blake2State constructed directly skipped that check, so a length of 65 did too.

Both paths now require a length from 1 through crypto_generichash_BYTES_MAX before the C call. Length 1 still returns a one-byte digest. Lengths 0, -1, and 65 raise ValueError.

tests/test_generichash.py: 2137 passed, 4 skipped. The rest of the suite was not run.

libsodium treats an output length of 0 or above 64 as misuse. A directly constructed state reached that call.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

generichash_blake2b_final() aborts for digest size 0

1 participant