{"id":"RUSTSEC-2026-0330","summary":"Hybrid Encapsulation from Seed Panics on Short Seed","details":"For a hybrid KEM public key of type `PublicKey::WingKemDraft06` or `PublicKey::X25519MlKem768Draft06`, the `PublicKey::encapsulate_derand` function would panic in an indexing operation on a seed input of length shorter than 32 bytes.\n\n# Impact\n\nApplications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.\n\n# Mitigation\n\nWith release of version `0.0.10` of `libcrux-kem` this bug has been fixed and the serialization functions return `InvalidPrivateKey` and `InvalidPublicKey` errors on invalid input buffer lengths.\n\nWe recommend users upgrade to `libcrux-kem` version `0.0.10`.","modified":"2026-10-07T08:30:02.862241231Z","published":"2026-09-28T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/libcrux-kem"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0330.html"},{"type":"WEB","url":"https://github.com/celabshq/libcrux/pull/1595"}],"affected":[{"package":{"name":"libcrux-kem","ecosystem":"crates.io","purl":"pkg:cargo/libcrux-kem"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.0.10"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"os":[],"functions":["libcrux_kem::PublicKey::encapsulate_derand"],"arch":[]}},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0330.json","categories":[],"cvss":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","informational":null}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}