{"id":"RUSTSEC-2026-0329","summary":"Auto-Reseeding HMAC-DRBG could panic for some output lengths","details":"The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by `65_536`, the maximum number of output bytes that can be generated before reseeding has to happen.\n\n# Impact\n\nAn application relying on `libcrux-hmac-drgb` to provide randomness of byte length a non-zero integer multiple of `65_536` in a single call to `fill_bytes` would panic.\n\nAny calls with output buffer lengths not cleanly divisible by `65_536` are not affected.\n\n# Mitigation\n\nWith release the release of version `0.0.2` of `libcrux-hmac-drbg` this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.\n\nWe recommend users upgrade to `libcrux-hmac-drbg` version `0.0.2`.","modified":"2026-10-07T08:30:02.846769865Z","published":"2026-08-03T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/libcrux-hmac-drbg"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0329.html"},{"type":"WEB","url":"https://github.com/celabshq/libcrux/pull/1558"}],"affected":[{"package":{"name":"libcrux-hmac-drbg","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-hmac-drbg"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.0.2"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"functions":["libcrux_hmac_drbg::HmacDrbgRng::fill_bytes"],"arch":[],"os":[]}},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0329.json","cvss":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","informational":null,"categories":[]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}