{"id":"RUSTSEC-2026-0329","title":"Auto-Reseeding HMAC-DRBG could panic for some output lengths","summary":"Auto-Reseeding HMAC-DRBG could panic for some output lengths","severity":"none","vendor":"libcrux-hmac-drbg","product":"libcrux-hmac-drbg","ecosystem":"rust","affected":["libcrux-hmac-drbg >= 0.0.0-0, < 0.0.2"],"patched":["libcrux-hmac-drbg 0.0.2"],"published":"2026-08-03","updated":"2026-10-07","sourceUpdated":"2026-10-07T08:30:02.846769865Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0329","references":[{"url":"https://crates.io/crates/libcrux-hmac-drbg"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0329.html"},{"url":"https://github.com/celabshq/libcrux/pull/1558"}],"tags":["osv","rust"],"ingestedAt":"2026-10-08T07:34:51.739Z","slug":"RUSTSEC-2026-0329","body":"## Overview\n\nThe automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by `65_536`, the maximum number of output bytes that can be generated before reseeding has to happen.\n\n# Impact\n\nAn application relying on `libcrux-hmac-drgb` to provide randomness of byte length a non-zero integer multiple of `65_536` in a single call to `fill_bytes` would panic.\n\nAny calls with output buffer lengths not cleanly divisible by `65_536` are not affected.\n\n# Mitigation\n\nWith release the release of version `0.0.2` of `libcrux-hmac-drbg` this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.\n\nWe recommend users upgrade to `libcrux-hmac-drbg` version `0.0.2`.\n\n## Affected packages\n\n- `libcrux-hmac-drbg >= 0.0.0-0, < 0.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `libcrux-hmac-drbg 0.0.2`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}