HIGH
GHSA-fhvh-vw7h-9xf3
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
Details
The AVX2 implementation of ML-DSA verification incorrectly implemented the `use_hint` function, mishandling an edge case that should lead to signature rejection.
## Impact An attacker could make the ML-DSA verifier accept a crafted invalid signature under a maliciously generated verification key, if the AVX2 implementation is used.
## Mitigation From version `0.0.9` the edge case is handled correctly and invalid signatures are rejected.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/libcrux-ml-dsa
Introduced in:
0Fixed in: 0.0.9Upgrade libcrux-ml-dsa to 0.0.9 or newer (ecosystem crates.io).