CVE Request: Cryptography 1.5.3: HKDF might return an empty byte-string

From: Andrej Nemec <anemec () redhat com>
Date: Tue, 8 Nov 2016 14:06:14 +0100

A security issue was fixed in Cryptography 1.5.3 and disclosed publicly
in the changelog, posted below:

1.5.3 - 2016-11-05

* Security issue: Fixed a bug where HKDF would return an empty
byte-string if used with a length less than algorithm.digest_size.
Credit to Markus Döring for reporting the issue.



Upstream bug:


Upstream patch:


