[php-src] PR #24203: ext/standard: Validate the bcrypt cost before reading it

From: Date: Thu, 08 Oct 2026 19:52:17 +0000
Subject: [php-src] PR #24203: ext/standard: Validate the bcrypt cost before reading it
Groups: php.git-pulls 
Request: Send a blank email to git-pulls+get-39269@lists.php.net to get a copy of this message
Pull Request: https://github.com/php/php-src/pull/24203 Author: iliaal password_get_info() and password_needs_rehash() treat any 60-byte $2y hash as bcrypt and parse its cost with sscanf(), so a malformed hash such as $2y$32$... reports cost 32, and a run of 56 digits overflows zend_long. Such hashes now report as unknown, matching the two-digit 04-31 range crypt() accepts. password_verify() is unchanged because it still passes unidentified hashes to crypt(). The argon2 parameter parsing uses the same unbounded sscanf() and is left for a separate change.

« previous php.git-pulls (#39269) next »