<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T02:57:49.765078+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266800</id>
    <title>EUVD-2026-266800</title>
    <updated>2026-10-06T02:57:49.818772+00:00</updated>
    <content>EUVD-2026-266800</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24850</id>
    <title>fkie_cve-2026-24850</title>
    <updated>2026-10-06T02:57:49.818811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&lt;=` instead of `&lt;`), allowing duplicate indices. This is a regression bug. The original implementation was correct, but a commit in version 0.0.4 inadvertently changed the strict `&lt;` comparison to `&lt;=`, introducing the vulnerability. Version 0.1.0-rc.4 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5x2r-hc65-25f9</id>
    <title>GHSA-5x2r-hc65-25f9 — ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices</title>
    <updated>2026-10-06T02:57:49.818849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: ml-dsa</p>
<p>**Affected Crate:** `ml-dsa`  
**Affected Versions:** v0.1.0-rc.2 (and commits since `b01c3b7`)  
**Severity:** Medium  
**Reporter:** Oren Yomtov (Fireblocks)</p>
<p>## Summary</p>
<p>The ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&lt;=` instead of `&lt;`), allowing duplicate indices.</p>
<p>**Note:** This is a regression bug. The original implementation was correct, but commit `b01c3b7` ("Make ML-DSA signature decoding follow the spec (#895)", fixing issue #894) inadvertently changed the strict `&lt;` comparison to `&lt;=`, introducing the vulnerability.</p>
<p>## Vulnerability Details</p>
<p>### Root Cause</p>
<p>The vulnerability is located in the `monotonic` helper function in `ml-dsa/src/hint.rs`:</p>
<p>```rust
fn monotonic(a: &amp;[usize]) -&gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &lt;= *x)
}
```</p>
<p>The comparison operator `&lt;=` allows equal consecutive values, meaning duplicate hint indices are not rejected. The correct implementation should use strict less-than (`&lt;`):</p>
<p>```rust
fn monotonic(a: &amp;[usize]) -&gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &lt; *x)
}
```</p>
<p>### Regression Analysis</p>
<p>- **Original correct code** (commit `1d3a1d1` - "Add support for ML-DSA (#877)"): Used `&lt;` (strict)
- **Bu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5x2r-hc65-25f9"/>
  </entry>
</feed>
