Skip to content

ext/hash: improve PBKDF2 performance - #24188

Open
Sjord wants to merge 2 commits into
php:PHP-8.2from
Sjord:pbkdf2-perf-bug-82
Open

Sjord wants to merge 2 commits into
php:PHP-8.2from
Sjord:pbkdf2-perf-bug-82

Conversation

@Sjord

@Sjord Sjord commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This is a security bug, since it makes PBKDF2 faster for attackers than defenders. So it should be fixed from PHP 8.2 on.

This is a security bug, since it makes PBKDF2 faster for attackers than
defenders. So it should be fixed from PHP 8.2 on.

Fixes php#9604
@Sjord
Sjord force-pushed the pbkdf2-perf-bug-82 branch from 0e39d92 to 690e0ac Compare October 8, 2026 07:56
@Sjord
Sjord marked this pull request as draft October 8, 2026 09:31

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have you benchmarked the difference between it? Generally we treat performance improvements as a feature to be landed on master only and only vulnerbility fixes qualifies for 8.2. @php/release-managers-82 ?

Comment thread NEWS
due to partial address comparison). (CVE-2026-91768) (Alexandre Daubois)

- Hash:
. Improved performance of hash_pbkdf2. (Sjoerd Langkemper)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Feel free to add a UPGRADING entry.

@Sjord Sjord changed the title Improve PBKDF2 performance ext/hash: improve PBKDF2 performance Oct 8, 2026
@Sjord

Sjord commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

time sapi/cli/php -r 'hash_pbkdf2("sha256", "pass", "salt", 1e7);'

  • PHP-8.2: 18 seconds
  • this branch: 10 seconds

@Sjord
Sjord marked this pull request as ready for review October 8, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants