PT-2021-28378 · Aes · Aes

Published

2021-04-29

·

Updated

2021-04-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: aes crate (affected versions not specified)
Description: The aes crate has been updated to autodetect AES-NI at runtime on i686/x86-64 platforms. If AES-NI is not present, it falls back to a constant-time portable software implementation.
Recommendations: To ensure constant-time portable implementation is used, even if AES-NI is available, use the force-soft feature of the aes crate to disable autodetection. At the moment, there is no information about a newer version that contains a fix for this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2021-0060

Affected Products

Aes