Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-435g-fcv3-8j26

Опубликовано: 12 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 0

Описание

Bug-Fixes in libcrux-ecdh, libcrux-ed25519, libcrux-psq

In accordance with our security policy for libcrux, we publish a GitHub security advisory for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade. The latest releases of the libcrux-ecdh, libcrux-ed25519 and libcrux-psq crates contain the following bug-fixes:

libcrux-ecdh

  • #1301: Check length and clamping in X25519 secret validation. This is a breaking change since errors are now raised on unclamped X25519 secrets or inputs of the wrong length

libcrux-ed25519

  • #1320: Remove duplicated clamping step during key generation

The issue fixed in #1320 was first reported by Nadim Kobeissi.

libcrux-psq

  • #1319: Propagate AEADError instead of panicking
  • #1301: Fix broken clamping check for imported X25519 secret keys

The issue fixed in #1319 was first reported by Nadim Kobeissi.

Пакеты

Наименование

libcrux-ecdh

rust
Затронутые версииВерсия исправления

<= 0.0.5

0.0.6

Наименование

libcrux-ed25519

rust
Затронутые версииВерсия исправления

<= 0.0.5

0.0.6

Наименование

libcrux-psq

rust
Затронутые версииВерсия исправления

<= 0.0.6

0.0.7

0 Low

CVSS4

Дефекты

CWE-20
CWE-327

0 Low

CVSS4

Дефекты

CWE-20
CWE-327