#1698 libdhash: hash table subject algorithmic complexity attacks
Closed Opened by jhrozek.

https://bugzilla.redhat.com/show_bug.cgi?id=882334 (Red Hat Enterprise Linux 6)

The internal hash function for strings uses this construct:
        for (h = 0, k = (unsigned char *) key->str; *k; k++)
            h = h * PRIME_1 ^ (*k - ' ');
It might be a good idea to switch to a keyed hash function (like Bob Jenkins'
lookup3 function).
I don't know if libdhash is used in ways that expose this and allow attackers
to mount algorithmic complexity denial-of-service attacks (a few thousand
entries with attacker-controlled keys would be needed), or if client code
depends on the predictable iteration order.

Fields changed

blockedby: =>
blocking: =>
coverity: =>
design: =>
design_review: => 0
feature_milestone: =>
fedora_test_page: =>
milestone: NEEDS_TRIAGE => SSSD 1.10 beta
testsupdated: => 0

Fields changed

blockedby: =>
blocking: =>
coverity: =>
design: =>
design_review: => 0
feature_milestone: =>
fedora_test_page: =>
milestone: NEEDS_TRIAGE => SSSD 1.10 beta
testsupdated: => 0

Fields changed

blockedby: =>
blocking: =>
coverity: =>
design: =>
design_review: => 0
feature_milestone: =>
fedora_test_page: =>
milestone: NEEDS_TRIAGE => SSSD 1.10 beta
testsupdated: => 0

Fields changed

selected: => Not need

Fields changed

selected: => Not need

Fields changed

selected: => Not need

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

Just FYI, the current recommended hash function is Siphash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all.

_comment0: Just FYI, the current recommended hash function is SipHash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all. => 1359043587232935

Just FYI, the current recommended hash function is Siphash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all.

_comment0: Just FYI, the current recommended hash function is SipHash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all. => 1359043587232935

Just FYI, the current recommended hash function is Siphash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all.

_comment0: Just FYI, the current recommended hash function is SipHash, so we will need to implement it before we can address this libdhash issue if we determine we need any change at all. => 1359043587232935

Fields changed

changelog: =>
milestone: SSSD 1.13 beta => Tools Deferred
review: => 0

Fields changed

changelog: =>
milestone: SSSD 1.13 beta => Tools Deferred
review: => 0

Fields changed

changelog: =>
milestone: SSSD 1.13 beta => Tools Deferred
review: => 0

Metadata Update from @jhrozek:
- Issue set to the milestone: Tools Deferred

Ticket is moved out of sssd issue tracker.

https://pagure.io/SSSD/ding-libs/issue/1698

Metadata Update from @lslebodn:
- Custom field component reset
- Custom field design_review reset
- Custom field patch reset
- Custom field review reset
- Custom field selected reset
- Custom field testsupdated reset
- Custom field type reset
- Issue close_status updated to: None

Metadata Update from @lslebodn:
- Custom field design_review reset
- Custom field patch reset
- Custom field review reset
- Custom field testsupdated reset
- Issue status updated to: Closed (was: Open)

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/2740

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata