PT-2026-60830 · Crates.Io · Libcrux-Aesgcm

Published

2026-06-09

·

Updated

2026-06-09

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
NIST Special Publication 800-38D specifies that the bit length of the AAD shall not exceed 2^64 - 1 bits. The implementation of AES-GCM in libcrux-aesgcm neither enforced this limit for encryption nor for decryption.

Impact

Use of AES-GCM with AAD of length exceeding the prescribed maximum length degrades the authentication security of the GCM tag.

Mitigation

Starting from version 0.0.9 (published as libcrux-aes@v0.0.9), limits on the length of the AAD input are enforced, so overlong AAD inputs result in an error on encryption and decryption.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0209

Affected Products

Libcrux-Aesgcm