RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0330

Hybrid Encapsulation from Seed Panics on Short Seed

Reported
Issued
Package
libcrux-kem (crates.io)
Type
Vulnerability
References
CVSS Score
5.6 MEDIUM
CVSS Details
Attack Complexity
Low
Attack Requirements
Present
Attack Vector
Local
Privileges Required
High
Availability Impact to the Subsequent System
None
Confidentiality Impact to the Subsequent System
None
Integrity Impact to the Subsequent System
None
User Interaction
None
Availability Impact to the Vulnerable System
High
Confidentiality Impact to the Vulnerable System
None
Integrity Impact to the Vulnerable System
None
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Patched
  • >=0.0.10
Affected Functions
Version
libcrux_kem::PublicKey::encapsulate_derand
  • <=0.0.9

Description

For a hybrid KEM public key of type PublicKey::WingKemDraft06 or PublicKey::X25519MlKem768Draft06, the PublicKey::encapsulate_derand function would panic in an indexing operation on a seed input of length shorter than 32 bytes.

Impact

Applications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.

Mitigation

With release of version 0.0.10 of libcrux-kem this bug has been fixed and the serialization functions return InvalidPrivateKey and InvalidPublicKey errors on invalid input buffer lengths.

We recommend users upgrade to libcrux-kem version 0.0.10.

Advisory available under CC0-1.0 license.