GHSA-hc3c-63hc-2r9f
libcrux: Potential Panic on Overlong Ciphertext Buffer
Details
An application that passes in a ciphertext buffer of length greater than `ptxt.len() + TAG_LEN` to `libcrux_chacha20poly1305::encrypt` or `libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` would experience a panic.
## Impact An application where the length of the ciphertext buffer is under attacker control could be made to crash.
## Mitigation The fix makes it so that `libcrux_chacha20poly1305::encrypt` and `libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` no longer panic in this case, but instead write out the ciphertext and tag into the first `ptxt.len() + TAG_LEN` bytes of the provided buffer.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.0.8Upgrade libcrux-chacha20poly1305 to 0.0.8 or newer (ecosystem crates.io).