Intel

AIKIDO-2026-71024

libcrux-secrets is vulnerable to Incorrect Comparison

Incorrect Comparison Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Today

82

High Risk

This Affects:

RUSTlibcrux-secrets
0.0.0 - 0.0.5
Fixed in 0.0.6
Are you affected? Scan for Free

TL;DR

A flaw in the constant-time swap and select implementations on AArch64 platforms could cause incorrect results due to an improper comparison in inline assembly. The comparison instruction evaluated unintended high-order bits of an 8-bit selector, potentially causing the operation to produce incorrect output under certain execution environments. Applications relying on these primitives for cryptographic operations could be affected by incorrect behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

libcrux-secrets is vulnerable to Incorrect Comparison in versions 0.0.0 - 0.0.5.

How to fix this

Upgrade the libcrux-secrets library to the patch version.