php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #68328 hash_equals does not mention that a difference in str length will leak
Submitted: 2014-10-30 07:27 UTC Modified: 2014-10-30 10:07 UTC
From: asphp at dsgml dot com Assigned: mikemike (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
 [2014-10-30 07:27 UTC] asphp at dsgml dot com
Description:
------------
---
From manual page: http://www.php.net/function.hash-equals
---

You should document that hash_equals will immediately return false if the strings differ in length.

It doesn't even try to compare the strings up to whichever is shorter. It just returns false right away.

In some applications this is a problem, so it should be documented.

Note: See also Bug #67939


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-10-30 09:26 UTC] mikemike@php.net
There is already a note present, which reads:

--
Note:
Both arguments must be of the same length to be compared successfully. When arguments of differing length are supplied, FALSE is returned and the length of the known string may be leaked in case of a timing attack.
--

Can you supply an instance where returning false is an issue?
 [2014-10-30 09:38 UTC] asphp at dsgml dot com
I did not see the note.

The information in it should be added to the Description near "This function should be used to mitigate timing attacks".
 [2014-10-30 09:40 UTC] asphp at dsgml dot com
Also on the note change it to say "FALSE is returned immediately and the". (i.e. add the word immediately.)
 [2014-10-30 10:04 UTC] mikemike@php.net
Automatic comment from SVN on behalf of mikemike
Revision: http://svn.php.net/viewvc/?view=revision&revision=335150
Log: Added word 'immediately' to add clarity, address bug #68328
 [2014-10-30 10:05 UTC] mikemike@php.net
-Assigned To: +Assigned To: mikemike
 [2014-10-30 10:07 UTC] mikemike@php.net
A patch has been added reflecting this change.  It may take a few hours to make its way across all mirrors.

Thank you
 [2014-10-30 10:07 UTC] mikemike@php.net
-Status: Assigned +Status: Closed
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 03:00:02 2026 UTC