VDB
Sign up
—

RUSTSEC-2026-0074

Incorrect Output of Incremental Portable SHAKE API

Details

The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than `RATE` (168 for SHAKE128, 136 for SHAKE256) bytes, performed an additional permutation of the state before producing the first output block, thus discarding the first block of `RATE` bytes of valid XOF output.

## Impact This bug impacts users that rely on this XOF API to squeeze more than `RATE` bytes. It does not impact the use of libcrux-sha3 in libcrux-ml-kem or libcrux-ml-dsa.

## Mitigation Starting from version `0.0.8` the squeeze functions correctly output all blocks including the first block.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libcrux-sha3
Introduced in: 0.0.0-0Fixed in: 0.0.8

Upgrade libcrux-sha3 to 0.0.8 or newer (ecosystem crates.io).

References