RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0329

Auto-Reseeding HMAC-DRBG could panic for some output lengths

Reported
Issued
Package
libcrux-hmac-drbg (crates.io)
Type
Vulnerability
References
CVSS Score
8.2 HIGH
CVSS Details
Attack Complexity
Low
Attack Requirements
Present
Attack Vector
Network
Privileges Required
None
Availability Impact to the Subsequent System
None
Confidentiality Impact to the Subsequent System
None
Integrity Impact to the Subsequent System
None
User Interaction
None
Availability Impact to the Vulnerable System
High
Confidentiality Impact to the Vulnerable System
None
Integrity Impact to the Vulnerable System
None
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Patched
  • >=0.0.2
Affected Functions
Version
libcrux_hmac_drbg::HmacDrbgRng::fill_bytes
  • <=0.0.1

Description

The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65_536, the maximum number of output bytes that can be generated before reseeding has to happen.

Impact

An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65_536 in a single call to fill_bytes would panic.

Any calls with output buffer lengths not cleanly divisible by 65_536 are not affected.

Mitigation

With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.

We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.

Advisory available under CC0-1.0 license.