Bug 2064790
| Summary: | SHA384 in gnutls works only once | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Miroslav Lichvar <mlichvar> |
| Component: | gnutls | Assignee: | Daiki Ueno <dueno> |
| Status: | CLOSED WONTFIX | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.5 | Keywords: | Triaged |
| Target Milestone: | rc | Flags: | pm-rhel:
mirror+
|
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-03-22 07:58:27 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2062356 | ||
|
Description
Miroslav Lichvar
2022-03-16 14:49:12 UTC
I guess this could be worked around by not using gnutls_hash_copy but always create a new context, but it's not acceptable because of performance, right? Yes, in the chrony case the hash context is reused for performance reasons and to avoid unnecessary memory allocations. It does not call gnutls_hash_copy(), it relies on gnutls_hash_output() resetting the state. |