PT-2026-107470 · Crates.Io · Libcrux-Hmac-Drbg

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65 536, the maximum number of output bytes that can be generated before reseeding has to happen.

Impact

An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65 536 in a single call to fill bytes would panic.
Any calls with output buffer lengths not cleanly divisible by 65 536 are not affected.

Mitigation

With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.
We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0329

Affected Products

Libcrux-Hmac-Drbg