PT-2026-41337 · Crates.Io · Libcrux-Ml-Dsa

Published

2026-05-05

·

Updated

2026-05-05

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
The AVX2 implementation of ML-DSA verification incorrectly implemented the use hint function, mishandling an edge case that should lead to signature rejection.

Impact

An attacker could make the ML-DSA verifier accept a crafted invalid signature under a maliciously generated verification key, if the AVX2 implementation is used.

Mitigation

From version 0.0.9 the edge case is handled correctly and invalid signatures are rejected.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0125

Affected Products

Libcrux-Ml-Dsa