VDB
Sign up
HIGH

GHSA-fhvh-vw7h-9xf3

libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case

Details

The AVX2 implementation of ML-DSA verification incorrectly implemented the `use_hint` function, mishandling an edge case that should lead to signature rejection.

## Impact An attacker could make the ML-DSA verifier accept a crafted invalid signature under a maliciously generated verification key, if the AVX2 implementation is used.

## Mitigation From version `0.0.9` the edge case is handled correctly and invalid signatures are rejected.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libcrux-ml-dsa
Introduced in: 0Fixed in: 0.0.9

Upgrade libcrux-ml-dsa to 0.0.9 or newer (ecosystem crates.io).

References