An application that passes in a ciphertext buffer of length greater
than ptxt.len() + TAG_LEN to libcrux_chacha20poly1305::encrypt or
libcrux_chacha20poly1305::xchacha20_poly1305::encrypt would
experience a panic.
An application where the length of the ciphertext buffer is under
attacker control could be made to crash.
The fix makes it so that libcrux_chacha20poly1305::encrypt and
libcrux_chacha20poly1305::xchacha20_poly1305::encrypt no longer
panic in this case, but instead write out the ciphertext and tag into
the first ptxt.len() + TAG_LEN bytes of the provided buffer.
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.2 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-hc3c-63hc-2r9f ↗ |
| CWE id | Name |
|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| rust | libcrux-chacha20poly1305 | < 0.0.8 | 0.0.8 | — |