Intel

AIKIDO-2026-354928

libcrux-sha3 is vulnerable to Incorrect Calculation

Incorrect Calculation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

82

High Risk

This Affects:

RUSTlibcrux-sha3
0.0.0 - 0.0.9
Fixed in 0.0.10
Are you affected? Scan for Free

TL;DR

A flaw in the portable SHAKE XOF incremental squeeze implementation could produce incorrect output when the output is retrieved across multiple squeeze calls with lengths that are not divisible by the algorithm's rate. Due to improper buffering of partially consumed output blocks, bytes could be dropped, resulting in incorrect cryptographic output and potentially compromising applications that rely on the API for incremental SHAKE operations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you are using the libcrux_sha3::portable::incremental::Shake128Xof::squeeze or libcrux_sha3::portable::incremental::Shake256Xof::squeeze functions.

Background info

libcrux-sha3 is vulnerable to Incorrect Calculation in versions 0.0.0 - 0.0.9.

How to fix this

Upgrade the libcrux-sha3 library to the patch version.