VDB
Sign up
CRITICAL9.8

PYSEC-2026-504

Buffer overflow in sponge queue functions

Details

### Impact

The Keccak sponge function interface accepts partial inputs to be absorbed and partial outputs to be squeezed. A buffer can overflow when partial data with some specific sizes are queued, where at least one of them has a length of 2^32 - 200 bytes or more.

### Patches

Yes, see commit [fdc6fef0](https://github.com/XKCP/XKCP/commit/fdc6fef075f4e81d6b1bc38364248975e08e340a). ### Workarounds

The problem can be avoided by limiting the size of the partial input data (or partial output digest) below 2^32 - 200 bytes. Multiple calls to the queue system can be chained at a higher level to retain the original functionality. Alternatively, one can process the entire input (or produce the entire output) at once, avoiding the queuing functions altogether.

### References

See [issue #105](https://github.com/XKCP/XKCP/issues/105) for more details.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pysha3
Introduced in: 0

No fixed version published yet for pysha3 (pip). Pin to a known-safe version or switch to an alternative.

References