---
id: RUSTSEC-2026-0290
title: >-
  pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling
  chosen-ciphertext key recovery
summary: >-
  pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling
  chosen-ciphertext key recovery
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: pqc_kyber
product: pqc_kyber
ecosystem: rust
affected:
  - pqc_kyber >= 0.0.0-0
published: '2026-08-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T09:15:05.128982400Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0290'
references:
  - url: 'https://crates.io/crates/pqc_kyber'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0290.html'
  - url: 'https://github.com/Argyle-Software/kyber/pull/121'
tags:
  - osv
  - rust
ingestedAt: '2026-09-18T16:21:29.497Z'
---

## Overview

## Summary

When `pqc_kyber` is built with the opt-in `avx2` feature on x86_64, its
constant-time conditional-move routine `cmov` is a no-op: it never performs the
copy. That `cmov` is exactly the step that applies the Fujisaki-Okamoto (FO)
implicit rejection during decapsulation. With it disabled, decapsulating an
*invalid* ciphertext no longer returns a key-independent pseudorandom value;
it returns a value that depends on the decrypted plaintext of the
attacker-chosen ciphertext. This restores the chosen-ciphertext decryption
oracle that the FO transform exists to remove, and yields full recovery of the
static secret key.

The attack requires no timing measurement, no side channel, and no faults; only
the ability to submit ciphertexts to a decapsulation operation under a reused
key pair and observe the resulting shared secret. See the linked pull request
for the root cause, the reachable call path, and reproduction details.

## Affected configuration

Reachable only in builds with `features = ["avx2"]` on an x86_64 target. The
default (reference) backend and all non-x86_64 targets are unaffected.

## Impact

Complete IND-CCA break. The plaintext-checking oracle drives a standard
chosen-ciphertext key-recovery attack and extracts the entire static secret
key. Any protocol reusing a Kyber key pair across decapsulations (static or
long-term KEM keys, KEMTLS, HPKE recipients, pinned keys) is exposed;
ephemeral-only key shares are not. The defect was verified end to end on
ML-KEM-768: the full secret key was recovered in 4,272 decapsulation queries.

## Maintenance status

The crate is unmaintained (last release 0.7.1, August 2023); no patched version
exists or is expected.

## Mitigation

- If remaining on this crate, do not enable the `avx2` feature; the default
  reference backend performs implicit rejection correctly.
- Do not reuse a Kyber key pair across decapsulations.

## Credit

Reported by 007bsd.

## Affected packages

- `pqc_kyber >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
