highVulnerability

GHSA-q29p-9pfr-j652

The incremental squeeze functions in the portable SHAKE XOF API, when attempting to squeeze more than `RATE` (168 for SHAKE128, 136 for SHAKE256) bytes, performed an additional permutation of the state before producing the first output block, thus discarding the first block of `RATE` bytes of valid XOF output. ## Impact This bug impacts users that rely on this XOF API to squeeze more than `RATE` bytes. It does not impact the use of libcrux-sha3 in libcrux-ml-kem or libcrux-ml-dsa. ## Mitigation Starting from version `0.0.8` the squeeze functions correctly output all blocks including the first block.

Properties

ghsa_id
GHSA-q29p-9pfr-j652
severity
high
summary
libcrux-sha3: Incorrect output from SHAKE squeeze functions
cve_id
GHSA-q29p-9pfr-j652
is_ghsa_only
true
ghsa_published
2026-03-26T17:59:34Z
source_url
https://github.com/advisories/GHSA-q29p-9pfr-j652
ghsa_updated
2026-03-26T17:59:35Z

Related Entities (3)

AFFECTS (1)

[Software]rust/libcrux-sha3

HAS_WEAKNESS (1)

[Weakness]Incorrect Calculation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-q29p-9pfr-j652 — Ninja Signal Threat Intelligence | Ninja Signal