<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:20:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266800</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266800</link>
      <description>EUVD-2026-266800</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266800</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24850</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24850</link>
      <description>&lt;p&gt;The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&amp;lt;=` instead of `&amp;lt;`), allowing duplicate indices. This is a regression bug. The original implementation was correct, but a commit in version 0.0.4 inadvertently changed the strict `&amp;lt;` comparison to `&amp;lt;=`, introducing the vulnerability. Version 0.1.0-rc.4 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&amp;lt;=` instead of `&amp;lt;`), allowing duplicate indices. This is a regression bug. The original implementation was correct, but a commit in version 0.0.4 inadvertently changed the strict `&amp;lt;` comparison to `&amp;lt;=`, introducing the vulnerability. Version 0.1.0-rc.4 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24850</guid>
    </item>
    <item>
      <title>GHSA-5x2r-hc65-25f9 — ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5x2r-hc65-25f9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: ml-dsa&lt;/p&gt;
&lt;p&gt;**Affected Crate:** `ml-dsa`  
**Affected Versions:** v0.1.0-rc.2 (and commits since `b01c3b7`)  
**Severity:** Medium  
**Reporter:** Oren Yomtov (Fireblocks)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&amp;lt;=` instead of `&amp;lt;`), allowing duplicate indices.&lt;/p&gt;
&lt;p&gt;**Note:** This is a regression bug. The original implementation was correct, but commit `b01c3b7` (&amp;#34;Make ML-DSA signature decoding follow the spec (#895)&amp;#34;, fixing issue #894) inadvertently changed the strict `&amp;lt;` comparison to `&amp;lt;=`, introducing the vulnerability.&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability is located in the `monotonic` helper function in `ml-dsa/src/hint.rs`:&lt;/p&gt;
&lt;p&gt;```rust
fn monotonic(a: &amp;amp;[usize]) -&amp;gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &amp;lt;= *x)
}
```&lt;/p&gt;
&lt;p&gt;The comparison operator `&amp;lt;=` allows equal consecutive values, meaning duplicate hint indices are not rejected. The correct implementation should use strict less-than (`&amp;lt;`):&lt;/p&gt;
&lt;p&gt;```rust
fn monotonic(a: &amp;amp;[usize]) -&amp;gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &amp;lt; *x)
}
```&lt;/p&gt;
&lt;p&gt;### Regression Analysis&lt;/p&gt;
&lt;p&gt;- **Original correct code** (commit `1d3a1d1` - &amp;#34;Add support for ML-DSA (#877)&amp;#34;): Used `&amp;lt;` (strict)
- **Bu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: ml-dsa&lt;/p&gt;
&lt;p&gt;**Affected Crate:** `ml-dsa`  
**Affected Versions:** v0.1.0-rc.2 (and commits since `b01c3b7`)  
**Severity:** Medium  
**Reporter:** Oren Yomtov (Fireblocks)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (duplicate) hint indices. According to the ML-DSA specification (FIPS 204 / RFC 9881), hint indices within each polynomial must be **strictly increasing**. The current implementation uses a non-strict monotonic check (`&amp;lt;=` instead of `&amp;lt;`), allowing duplicate indices.&lt;/p&gt;
&lt;p&gt;**Note:** This is a regression bug. The original implementation was correct, but commit `b01c3b7` (&amp;#34;Make ML-DSA signature decoding follow the spec (#895)&amp;#34;, fixing issue #894) inadvertently changed the strict `&amp;lt;` comparison to `&amp;lt;=`, introducing the vulnerability.&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability is located in the `monotonic` helper function in `ml-dsa/src/hint.rs`:&lt;/p&gt;
&lt;p&gt;```rust
fn monotonic(a: &amp;amp;[usize]) -&amp;gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &amp;lt;= *x)
}
```&lt;/p&gt;
&lt;p&gt;The comparison operator `&amp;lt;=` allows equal consecutive values, meaning duplicate hint indices are not rejected. The correct implementation should use strict less-than (`&amp;lt;`):&lt;/p&gt;
&lt;p&gt;```rust
fn monotonic(a: &amp;amp;[usize]) -&amp;gt; bool {
    a.iter().enumerate().all(|(i, x)| i == 0 || a[i - 1] &amp;lt; *x)
}
```&lt;/p&gt;
&lt;p&gt;### Regression Analysis&lt;/p&gt;
&lt;p&gt;- **Original correct code** (commit `1d3a1d1` - &amp;#34;Add support for ML-DSA (#877)&amp;#34;): Used `&amp;lt;` (strict)
- **Bu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5x2r-hc65-25f9</guid>
    </item>
  </channel>
</rss>
