Skip to content

RUSTSEC-2026-0207: Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls #21

Description

@github-actions

Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls

Details
Package libcrux-sha3
Version 0.0.8
URL celabshq/libcrux#1389
Date 2026-04-22
Patched versions >=0.0.10

The incremental squeeze functions in the portable SHAKE XOF API, when
attempting to squeeze an output using multiple calls to squeeze,
rather than squeezing the full output at once, could output incorrect
values. Internally, output blocks that were not completely squeezed
were not buffered for the next call to squeeze, which would
consequently drop bytes of the correct squeeze output if the preceding
call requested an output of length in bytes not cleanly divisible by
RATE (168 for SHAKE128, 136 for SHAKE256).

Impact

This bug impacts users that rely on this XOF API to squeeze output in
multiple calls where any of the calls request an output length that is
not divisible by RATE. It does not impact the use of libcrux-sha3 in
libcrux-ml-kem or libcrux-ml-dsa.

Mitigation

Starting from version 0.0.10 the squeeze functions correctly output
all squeezed bytes independent of the number of squeeze calls and
the output lengths requested in each call.

See advisory page for additional details.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions