RFR: 8311902: Concurrency regression in the PBKDF2 key impl of SunJCE provider

Valerie Peng valeriep at openjdk.org
Thu Jul 13 21:03:58 UTC 2023


On Thu, 13 Jul 2023 04:15:54 GMT, Xue-Lei Andrew Fan <xuelei at openjdk.org> wrote:

> It looks good to me to rollback to previous behaviors. I was just wondering, if the use of key in other methods, like hashCode()/equals(), has the similar issue? Thanks!

For the usage of hashCode()/equals(), there should be strong reference to the key object for the usage scenarios I'd think. Thus, probably not an issue?

-------------

PR Comment: https://git.openjdk.org/jdk/pull/14859#issuecomment-1634913864


More information about the security-dev mailing list