Security Advisories (1)
CVE-2026-41565 (2026-05-28)

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer (MAXBLOCKSIZE) without checking the supplied length. A longer tag overwrites the stack past the buffer. Version 0.088 added the clamp to gcm_decrypt_verify, and 0.088_001 added it to the other three. Any caller of an affected helper that forwards an attacker-controlled tag longer than the buffer can trigger the overflow.

NAME

Crypt::Digest::SHA3_224 - Hash function SHA3-224 [size: 224 bits]

SYNOPSIS

### Functional interface:
use Crypt::Digest::SHA3_224 qw( sha3_224 sha3_224_hex sha3_224_b64 sha3_224_b64u
                             sha3_224_file sha3_224_file_hex sha3_224_file_b64 sha3_224_file_b64u );

# calculate digest from string/buffer
$sha3_224_raw  = sha3_224('data string');
$sha3_224_hex  = sha3_224_hex('data string');
$sha3_224_b64  = sha3_224_b64('data string');
$sha3_224_b64u = sha3_224_b64u('data string');
# calculate digest from file
$sha3_224_raw  = sha3_224_file('filename.dat');
$sha3_224_hex  = sha3_224_file_hex('filename.dat');
$sha3_224_b64  = sha3_224_file_b64('filename.dat');
$sha3_224_b64u = sha3_224_file_b64u('filename.dat');
# calculate digest from filehandle
$sha3_224_raw  = sha3_224_file(*FILEHANDLE);
$sha3_224_hex  = sha3_224_file_hex(*FILEHANDLE);
$sha3_224_b64  = sha3_224_file_b64(*FILEHANDLE);
$sha3_224_b64u = sha3_224_file_b64u(*FILEHANDLE);

### OO interface:
use Crypt::Digest::SHA3_224;

$d = Crypt::Digest::SHA3_224->new;
$d->add('any data');
$d->addfile('filename.dat');
$d->addfile(*FILEHANDLE);
$result_raw  = $d->digest;     # raw bytes
$result_hex  = $d->hexdigest;  # hexadecimal form
$result_b64  = $d->b64digest;  # Base64 form
$result_b64u = $d->b64udigest; # Base64 URL Safe form

DESCRIPTION

Provides an interface to the SHA3_224 digest algorithm.

EXPORT

Nothing is exported by default.

You can export selected functions:

use Crypt::Digest::SHA3_224 qw(sha3_224 sha3_224_hex sha3_224_b64 sha3_224_b64u
                                    sha3_224_file sha3_224_file_hex sha3_224_file_b64 sha3_224_file_b64u);

Or all of them at once:

use Crypt::Digest::SHA3_224 ':all';

FUNCTIONS

sha3_224

Logically joins all arguments into a single string, and returns its SHA3_224 digest encoded as a binary string.

$sha3_224_raw = sha3_224('data string');
#or
$sha3_224_raw = sha3_224('any data', 'more data', 'even more data');

sha3_224_hex

Logically joins all arguments into a single string, and returns its SHA3_224 digest encoded as a hexadecimal string.

$sha3_224_hex = sha3_224_hex('data string');
#or
$sha3_224_hex = sha3_224_hex('any data', 'more data', 'even more data');

sha3_224_b64

Logically joins all arguments into a single string, and returns its SHA3_224 digest encoded as a Base64 string, with trailing '=' padding.

$sha3_224_b64 = sha3_224_b64('data string');
#or
$sha3_224_b64 = sha3_224_b64('any data', 'more data', 'even more data');

sha3_224_b64u

Logically joins all arguments into a single string, and returns its SHA3_224 digest encoded as a Base64 URL Safe string (see RFC 4648 section 5).

$sha3_224_b64url = sha3_224_b64u('data string');
#or
$sha3_224_b64url = sha3_224_b64u('any data', 'more data', 'even more data');

sha3_224_file

Reads file (defined by filename or filehandle) content, and returns its SHA3_224 digest encoded as a binary string.

$sha3_224_raw = sha3_224_file('filename.dat');
#or
$sha3_224_raw = sha3_224_file(*FILEHANDLE);

sha3_224_file_hex

Reads file (defined by filename or filehandle) content, and returns its SHA3_224 digest encoded as a hexadecimal string.

$sha3_224_hex = sha3_224_file_hex('filename.dat');
#or
$sha3_224_hex = sha3_224_file_hex(*FILEHANDLE);

BEWARE: You have to make sure that the filehandle is in binary mode before you pass it as argument to the addfile() method.

sha3_224_file_b64

Reads file (defined by filename or filehandle) content, and returns its SHA3_224 digest encoded as a Base64 string, with trailing '=' padding.

$sha3_224_b64 = sha3_224_file_b64('filename.dat');
#or
$sha3_224_b64 = sha3_224_file_b64(*FILEHANDLE);

sha3_224_file_b64u

Reads file (defined by filename or filehandle) content, and returns its SHA3_224 digest encoded as a Base64 URL Safe string (see RFC 4648 section 5).

$sha3_224_b64url = sha3_224_file_b64u('filename.dat');
#or
$sha3_224_b64url = sha3_224_file_b64u(*FILEHANDLE);

METHODS

The OO interface provides the same set of functions as Crypt::Digest.

new

$d = Crypt::Digest::SHA3_224->new();

clone

$d->clone();

reset

$d->reset();

add

$d->add('any data');
#or
$d->add('any data', 'more data', 'even more data');

addfile

$d->addfile('filename.dat');
#or
$d->addfile(*FILEHANDLE);

add_bits

$d->add_bits($bit_string);   # e.g. $d->add_bits("111100001010");
#or
$d->add_bits($data, $nbits); # e.g. $d->add_bits("\xF0\xA0", 16);

hashsize

$d->hashsize;
#or
Crypt::Digest::SHA3_224->hashsize();
#or
Crypt::Digest::SHA3_224::hashsize();

digest

$result_raw = $d->digest();

hexdigest

$result_hex = $d->hexdigest();

b64digest

$result_b64 = $d->b64digest();

b64udigest

$result_b64url = $d->b64udigest();

SEE ALSO