- Reported
-
- Issued
-
- Package
-
pqc_kyber
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#kyber
#ml-kem
#key-recovery
#fujisaki-okamoto
#ind-cca
#avx2
- References
-
- CVSS Score
- 7.4
HIGH
- CVSS Details
-
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality Impact
- High
- Integrity Impact
- High
- Availability Impact
- None
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Patched
-
no patched versions
Description
Summary
When pqc_kyber is built with the opt-in avx2 feature on x86_64, its
constant-time conditional-move routine cmov is a no-op: it never performs the
copy. That cmov is exactly the step that applies the Fujisaki-Okamoto (FO)
implicit rejection during decapsulation. With it disabled, decapsulating an
invalid ciphertext no longer returns a key-independent pseudorandom value;
it returns a value that depends on the decrypted plaintext of the
attacker-chosen ciphertext. This restores the chosen-ciphertext decryption
oracle that the FO transform exists to remove, and yields full recovery of the
static secret key.
The attack requires no timing measurement, no side channel, and no faults; only
the ability to submit ciphertexts to a decapsulation operation under a reused
key pair and observe the resulting shared secret. See the linked pull request
for the root cause, the reachable call path, and reproduction details.
Affected configuration
Reachable only in builds with features = ["avx2"] on an x86_64 target. The
default (reference) backend and all non-x86_64 targets are unaffected.
Impact
Complete IND-CCA break. The plaintext-checking oracle drives a standard
chosen-ciphertext key-recovery attack and extracts the entire static secret
key. Any protocol reusing a Kyber key pair across decapsulations (static or
long-term KEM keys, KEMTLS, HPKE recipients, pinned keys) is exposed;
ephemeral-only key shares are not. The defect was verified end to end on
ML-KEM-768: the full secret key was recovered in 4,272 decapsulation queries.
Maintenance status
The crate is unmaintained (last release 0.7.1, August 2023); no patched version
exists or is expected.
Mitigation
- If remaining on this crate, do not enable the
avx2 feature; the default
reference backend performs implicit rejection correctly.
- Do not reuse a Kyber key pair across decapsulations.
Credit
Reported by 007bsd.
Advisory available under CC0-1.0
license.