RUSTSEC-2026-0329None▾ SunlitAuto-Reseeding HMAC-DRBG could panic for some output lengths
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65_536, the maximum number of output bytes that can be generated before reseeding has to happen.
An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65_536 in a single call to fill_bytes would panic.
Any calls with output buffer lengths not cleanly divisible by 65_536 are not affected.
With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.
We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.
libcrux-hmac-drbg >= 0.0.0-0, < 0.0.2Upgrade to a patched release:
libcrux-hmac-drbg 0.0.2