CVE-2026-10097
Vulnerability Description
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-327
Source
NVD
Vendor
wolfSSL
Product
wolfSSL
Discussion (0)
Add Comment
No comments yet. Be the first!