Skip to content

Commit 2c7d494

Browse files
ext/sodium: revert addition of extendable output functions
The extendable output functions treated the state as a string, rather than an opaque object, and only validated the lengths of the strings before converting them to the underlying libsodium objects. Thus, incorrect state values could be used to trigger out of bounds reads or updates. The following constants are removed: - `SODIUM_CRYPTO_XOF_SHAKE128_BLOCKBYTES` - `SODIUM_CRYPTO_XOF_SHAKE128_STATEBYTES` - `SODIUM_CRYPTO_XOF_SHAKE256_BLOCKBYTES` - `SODIUM_CRYPTO_XOF_SHAKE256_STATEBYTES` - `SODIUM_CRYPTO_XOF_TURBOSHAKE128_BLOCKBYTES` - `SODIUM_CRYPTO_XOF_TURBOSHAKE128_STATEBYTES` - `SODIUM_CRYPTO_XOF_TURBOSHAKE256_BLOCKBYTES` - `SODIUM_CRYPTO_XOF_TURBOSHAKE256_STATEBYTES` The following functions are removed: - `sodium_crypto_xof_shake128()` - `sodium_crypto_xof_shake128_init()` - `sodium_crypto_xof_shake128_update()` - `sodium_crypto_xof_shake128_squeeze()` - `sodium_crypto_xof_shake256()` - `sodium_crypto_xof_shake256_init()` - `sodium_crypto_xof_shake256_update()` - `sodium_crypto_xof_shake256_squeeze()` - `sodium_crypto_xof_turboshake128()` - `sodium_crypto_xof_turboshake128_init()` - `sodium_crypto_xof_turboshake128_update()` - `sodium_crypto_xof_turboshake128_squeeze()` - `sodium_crypto_xof_turboshake256()` - `sodium_crypto_xof_turboshake256_init()` - `sodium_crypto_xof_turboshake256_update()` - `sodium_crypto_xof_turboshake256_squeeze()`
1 parent fac360c commit 2c7d494

6 files changed

Lines changed: 1 addition & 1037 deletions

File tree

0 commit comments

Comments
 (0)