Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-48566 Cherry-pick 8bef9ebb1b88cfa4b2a38b93fe4ea22015d8254a #44

Merged
merged 1 commit into from
Apr 17, 2024

Commits on Apr 11, 2024

  1. CVE-2022-48566 Cherry-pick 8bef9eb

    bpo-40791: Make compare_digest more constant-time. (pythonGH-23438) (pythonGH-23767)
    
    The existing volatile `left`/`right` pointers guarantee that the reads will all occur, but does not guarantee that they will be _used_. So a compiler can still short-circuit the loop, saving e.g. the overhead of doing the xors and especially the overhead of the data dependency between `result` and the reads. That would change performance depending on where the first unequal byte occurs. This change removes that optimization.
    
    (This is change GH-1 from https://bugs.python.org/issue40791 .)
    (cherry picked from commit 3172936)
    
    Co-authored-by: Devin Jeanpierre <[email protected]>
    (cherry picked from commit 8bef9eb)
    miss-islington authored and rickprice committed Apr 11, 2024
    Configuration menu
    Copy the full SHA
    0691da3 View commit details
    Browse the repository at this point in the history