highVulnerability

GHSA-fhvh-vw7h-9xf3

The AVX2 implementation of ML-DSA verification incorrectly implemented the `use_hint` function, mishandling an edge case that should lead to signature rejection. ## Impact An attacker could make the ML-DSA verifier accept a crafted invalid signature under a maliciously generated verification key, if the AVX2 implementation is used. ## Mitigation From version `0.0.9` the edge case is handled correctly and invalid signatures are rejected.

Properties

ghsa_id
GHSA-fhvh-vw7h-9xf3
summary
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
severity
high
cve_id
GHSA-fhvh-vw7h-9xf3
is_ghsa_only
true
ghsa_published
2026-05-19T16:18:53Z
source_url
https://github.com/advisories/GHSA-fhvh-vw7h-9xf3
ghsa_updated
2026-05-19T16:18:57Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/libcrux-ml-dsa

AFFECTS (1)

[Software]rust/libcrux-ml-dsa

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

Explore deeper with Ninja Signal's threat intelligence graph