Skip to content

blake2: reject a digest size below 1 - #166

Merged
dinosaure merged 1 commit into
mirage:mainfrom
samoht:fix-blake2-digest-size
Jun 26, 2026
Merged

dinosaure merged 1 commit into
mirage:mainfrom
samoht:fix-blake2-digest-size

Conversation

@samoht

@samoht samoht commented Jun 25, 2026

Copy link
Copy Markdown
Member

Make_BLAKE2 only checks the upper bound on digest_size, so a size below 1 (e.g. -1) is accepted; in the C backend it wraps to a uint8_t (255) and finalise writes past the caller's destination buffer. Reject digest_size < 1 as well, in both the C and pure-OCaml backends.

Make_BLAKE2 only checked the upper bound on digest_size, so a size below 1 (e.g. -1) was accepted; in the C backend it wraps to a uint8_t (255) and finalise writes past the caller's destination buffer. Reject digest_size < 1 as well, in both the C and pure-OCaml backends.
@dinosaure

Copy link
Copy Markdown
Member

Thanks.

@dinosaure
dinosaure merged commit badbead into mirage:main Jun 26, 2026
2 of 4 checks passed
jmid pushed a commit to ocaml/opam-repository that referenced this pull request Jul 14, 2026
CHANGES:

- Remove DKML CI (@jonahbeckford, @dinosaure, mirage/digestif#159, mirage/digestif#160, mirage/digestif#161)
- Fix documentation (@kit-ty-kate, @dinosaure, mirage/digestif#162)
- Reject bad digest size for BLAKE2 implementation (@samoht, @dinosaure, mirage/digestif#166)
- Delete old artifact for MirageOS 3.0 (@dinosaure, @vbgl, mirage/digestif#165, mirage/digestif#168)
- Be safe aligned on ARM architecture (@dinosaure, @hannesm, mirage/digestif#169)
craff pushed a commit to craff/opam-repository that referenced this pull request Jul 25, 2026
CHANGES:

- Remove DKML CI (@jonahbeckford, @dinosaure, mirage/digestif#159, mirage/digestif#160, mirage/digestif#161)
- Fix documentation (@kit-ty-kate, @dinosaure, mirage/digestif#162)
- Reject bad digest size for BLAKE2 implementation (@samoht, @dinosaure, mirage/digestif#166)
- Delete old artifact for MirageOS 3.0 (@dinosaure, @vbgl, mirage/digestif#165, mirage/digestif#168)
- Be safe aligned on ARM architecture (@dinosaure, @hannesm, mirage/digestif#169)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants