{"id":"GHSA-2cgv-28vr-rv6j","aliases":["RUSTSEC-2025-0133"],"url":"https://o3.security/vulnerability/GHSA-2cgv-28vr-rv6j","summary":"libcrux incorrectly calculates on aarch64","details":"On platforms without the `core::arch::aarch64::vxarq_u64` intrinsic, an unverified fallback in `libcrux-intrinsics` v0.0.3\npassed incorrect arguments and produced wrong results. This corrupted SHA-3 digests and caused `libcrux-ml-kem` and\n`libcrux-ml-dsa` to sample incorrectly, yielding incorrect shared secrets and invalid signatures.\n\nThe issue has been fixed in v0.0.4.","published":"2025-12-04T17:24:23Z","modified":"2026-02-22T23:20:55.220024Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"libcrux-intrinsics","fixedVersion":"0.0.4"},{"ecosystem":"crates.io","name":"libcrux-ml-kem","fixedVersion":"0.0.4"},{"ecosystem":"crates.io","name":"libcrux-ml-dsa","fixedVersion":"0.0.4"}],"fix":{"url":"https://github.com/cryspen/libcrux/pull/1222","label":"cryspen/libcrux#1222"},"references":[{"type":"WEB","url":"https://github.com/cryspen/libcrux/issues/1220"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/pull/1222"},{"type":"WEB","url":"https://github.com/cryspen/libcrux/commit/8d10f45631afd1d93fabb2278dbb388a075b5608"},{"type":"PACKAGE","url":"https://github.com/cryspen/libcrux"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0133.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-22T23:20:55.220024Z"}}