PT-2026-27355 · Crates.Io · Libcrux-Poly1305
Published
2026-03-04
·
Updated
2026-03-04
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
An incorrect constant for the key length in libcrux-poly1305 caused
the standalone MAC function
libcrux poly1305::mac to always panic
with an out-of-bounds memory access.Impact
Applications wishing to use libcrux-poly1305 as a standalone MAC would
experience panics. The use of libcrux-poly1305 in
libcrux-chacha20poly1305 is unaffected.
Mitigation
Starting from version
0.0.5, the correct value is used for the key
length constant.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libcrux-Poly1305