[php-src] PR #24079: ext/openssl: Add validation for XOF digests requiring explicit output length
| From: | adapik | Date: | Fri, 02 Oct 2026 15:33:27 +0000 |
| Subject: | [php-src] PR #24079: ext/openssl: Add validation for XOF digests requiring explicit output length | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39082@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24079
Author: adapik
Emit a warning when
openssl_digest() / openssl_x509_fingerprint() get XOF
algorithm without a length.
OpenSSL 3.4 removed the default output length of SHAKE128/256, so
EVP_DigestFinal() now fails without an error:
openssl_digest('abc', 'shake128') returns false
silently, while on OpenSSL 3.0 it returns 16 bytes. SHAKE128/256 are listed by
openssl_get_md_methods(), so users can reasonably pass them to these functions.
Suggested fix: "Unsupported digest algorithm: output length must be specified" when an XOF
digest fails. Fixed-length digests and older OpenSSL are unaffected.