Back to CVE List

CVE-2026-10097

Vulnerability Description

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-327
Source
NVD
Vendor
wolfSSL
Product
wolfSSL

External References

Discussion (0)

Add Comment

No comments yet. Be the first!