Vulnerability RUSTSEC-2026-0329

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
August 03, 2026 at 12:00 PM UTC
Auto-Reseeding HMAC-DRBG could panic for some output lengths
0.0.1
0.0.1

Summary

Auto-Reseeding HMAC-DRBG could panic for some output lengths

Details

The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65_536, the maximum number of output bytes that can be generated before reseeding has to happen.

Impact

An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65_536 in a single call to fill_bytes would panic.

Any calls with output buffer lengths not cleanly divisible by 65_536 are not affected.

Mitigation

With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.

We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.

Impacted packages

Timeline

Published
2 months ago
August 03, 2026 at 12:00 PM UTC
Fixed (0.0.2)
3 hours ago
October 07, 2026 at 06:33 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 08:30 AM UTC