{"id":"RUSTSEC-2026-0211","summary":"Non-constant time Authentication Tag Check in AES-GCM Decryption","details":"AES-GCM decryption used an implementation for checking the provided\nauthentication tag against the recomputed authentication tag that was\nintended to be constant-time, but resulted in non-constant-time code\ngeneration in certain circumstances.\nNote that `libcrux-aesgcm` does not give guarantees on constant-time\ncode generation and possible mitigations must be considered\non a best-effort basis.\n\n## Impact\nUsers of `libcrux-aesgcm` that expose a decryption oracle to an\nattacker, which allows repeatedly querying for the same ciphertext\nwere at risk from timing side-channel attacks, depending on their\ncompilation environment. In the worst case, this could lead to\nrecovery of the recomputed authentication tag by the attacker, which\nenables ciphertext forgery.\n\n## Mitigation\nStarting from version `0.0.9` (published as `libcrux-aes@v0.0.9`),\nAES-GCM decryption uses a different, best-effort constant-time\nimplementation of the tag check, which has been checked to reliably\nlead to constant time code generation, at the moment.","modified":"2026-07-17T11:45:03.695400116Z","published":"2026-07-14T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/libcrux-aesgcm"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0211.html"},{"type":"WEB","url":"https://github.com/celabshq/libcrux/pull/1528"}],"affected":[{"package":{"name":"libcrux-aesgcm","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-aesgcm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"arch":[],"os":[],"functions":["libcrux_aesgcm::AesGcm128Key::decrypt","libcrux_aesgcm::AesGcm256Key::decrypt","libcrux_aesgcm::aes_gcm_128::AesGcm128::decrypt","libcrux_aesgcm::aes_gcm_128::Key::decrypt","libcrux_aesgcm::aes_gcm_128::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_128::neon::Key::decrypt","libcrux_aesgcm::aes_gcm_128::neon::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_128::neon::NeonAesGcm128::decrypt","libcrux_aesgcm::aes_gcm_128::portable::Key::decrypt","libcrux_aesgcm::aes_gcm_128::portable::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_128::portable::PortableAesGcm128::decrypt","libcrux_aesgcm::aes_gcm_128::x64::Key::decrypt","libcrux_aesgcm::aes_gcm_128::x64::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_128::x64::X64AesGcm128::decrypt","libcrux_aesgcm::aes_gcm_256::AesGcm256::decrypt","libcrux_aesgcm::aes_gcm_256::Key::decrypt","libcrux_aesgcm::aes_gcm_256::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_256::neon::Key::decrypt","libcrux_aesgcm::aes_gcm_256::neon::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_256::neon::NeonAesGcm256::decrypt","libcrux_aesgcm::aes_gcm_256::portable::Key::decrypt","libcrux_aesgcm::aes_gcm_256::portable::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_256::portable::PortableAesGcm256::decrypt","libcrux_aesgcm::aes_gcm_256::x64::Key::decrypt","libcrux_aesgcm::aes_gcm_256::x64::KeyRef::decrypt","libcrux_aesgcm::aes_gcm_256::x64::X64AesGcm256::decrypt"]},"affected_functions":null},"database_specific":{"informational":null,"categories":["crypto-failure"],"cvss":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0211.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}