highVulnerability
GHSA-fhvh-vw7h-9xf3
The AVX2 implementation of ML-DSA verification incorrectly implemented the `use_hint` function, mishandling an edge case that should lead to signature rejection. ## Impact An attacker could make the ML-DSA verifier accept a crafted invalid signature under a maliciously generated verification key, if the AVX2 implementation is used. ## Mitigation From version `0.0.9` the edge case is handled correctly and invalid signatures are rejected.
Properties
- ghsa_id
- GHSA-fhvh-vw7h-9xf3
- summary
- libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
- severity
- high
- cve_id
- GHSA-fhvh-vw7h-9xf3
- is_ghsa_only
- true
- ghsa_published
- 2026-05-19T16:18:53Z
- source_url
- https://github.com/advisories/GHSA-fhvh-vw7h-9xf3
- ghsa_updated
- 2026-05-19T16:18:57Z
Related Entities (4)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]rust/libcrux-ml-dsa
AFFECTS (1)
→[Software]rust/libcrux-ml-dsa
HAS_WEAKNESS (1)
→[Weakness]Improper Verification of Cryptographic Signature
Explore deeper with Ninja Signal's threat intelligence graph