[php-src] PR #24203: ext/standard: Validate the bcrypt cost before reading it
| From: | iliaal | Date: | Thu, 08 Oct 2026 19:52:17 +0000 |
| Subject: | [php-src] PR #24203: ext/standard: Validate the bcrypt cost before reading it | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39269@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24203
Author: iliaal
password_get_info() and password_needs_rehash() treat any 60-byte $2y hash as bcrypt and parse its
cost with sscanf(), so a malformed hash such as $2y$32$... reports cost 32, and a run of 56 digits
overflows zend_long. Such hashes now report as unknown, matching the two-digit 04-31 range crypt()
accepts. password_verify() is unchanged because it still passes unidentified hashes to crypt(). The
argon2 parameter parsing uses the same unbounded sscanf() and is left for a separate change.