Ensure that HMAC objects are properly initialized
Offen
@picnixz arbeitet bereits daran.
Seit 15.8.2026.
extension-modules
type-bug
- Vorherrschende Sprache
- Python
- Sterne
- 77.2k
- Forks
- 35.9k
- PR-Merge-Kennzahlen
- PR-Kennzahlen ausstehend
Beschreibung
Bug report
Bug description:
This affects the following situations:
_hmac.new()frees an uninitialized HACL pointer when the key exceedsUINT32_MAX_hmac_HMAC_copy_implrunsHASHLIB_INIT_MUTEX(copy)after the falliblehmac_copy_state
The solution is simply to always entirely initialize the HMAC object before working with it. We also change the usage of PyObject_New to tp->tp_alloc directly so that we only alter fields for which the 0-value would not be suitable.
CPython versions tested on:
CPython main branch
Operating systems tested on:
No response
Linked PRs
- gh-155845
- gh-157036
- gh-157037
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Bewertung
Dieses Issue wurde noch nicht bewertet.