GHSA-fhvh-vw7h-9xf3: libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
highvulnerability
security
Source: GitHub Advisory DatabaseMay 19, 2026
Summary
This advisory describes a vulnerability in libcrux-ml-dsa (a cryptographic library) where signature verification produces incorrect results on AVX2 platforms (processors with a specific instruction set for fast computation) in certain edge cases. The content provided focuses on explaining how security vulnerabilities are rated and scored, but does not describe the actual technical details of the bug itself.
Classification
Attack SophisticationModerate
Affected Packages
libcrux-ml-dsa@< 0.0.9 (fixed: 0.0.9)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-fhvh-vw7h-9xf3
First tracked: May 19, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%