CVE-2026-6330

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating party could fail to detect a manipulated ciphertext and proceed without the standard's required implicit rejection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-25 22:17

Updated : 2026-06-27 19:50


NVD link : CVE-2026-6330

Mitre link : CVE-2026-6330

CVE.ORG link : CVE-2026-6330


JSON object : View

Products Affected

wolfssl

  • wolfssl
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm