RustSec issued high-severity advisories for pqc_kyber and its fork cosmian_kyber after identifying a broken AVX2 cmov implementation that bypasses Fujisaki-Okamoto implicit rejection during Kyber/ML-KEM decapsulation. On affected x86_64 builds compiled with the opt-in avx2 feature, malformed ciphertexts create a chosen-ciphertext plaintext-checking oracle that can recover a reused static secret key; testing against ML-KEM-768 recovered a complete key with 4,272 decapsulation queries, without timing attacks, side channels, or fault injection.
The defect stems from incorrect SIMD-mask construction for _mm256_blendv_epi8, which leaves the candidate plaintext in place instead of selecting the rejection value. Neither crate has a patched release: pqc_kyber is unmaintained and cosmian_kyber is a stale fork with an unanswered fix pull request. Organizations should disable the AVX2 feature on affected deployments, avoid reusing Kyber key pairs for decapsulation, and migrate to maintained implementations such as aws-lc-rs or graviola; default reference backends and non-x86_64 targets are not affected.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
RustSec issued advisories designating pqc_kyber and cosmian_kyber as unmaintained and recommended migration to maintained alternatives including aws-lc-rs or graviola.
RustSec issued high-severity advisories for pqc_kyber and cosmian_kyber, affecting x86_64 builds with the opt-in AVX2 feature. The advisories state that disabling AVX2, avoiding key-pair reuse, or migrating to maintained implementations mitigates the issue.
The cosmian_kyber crate was reported as unmaintained. Its unanswered corrective pull request and stale, unmaintained upstream mean no patched version is available.
The pqc_kyber crate was reported as unmaintained after no releases since version 0.7.1 and no maintainer activity in its upstream repository. An unresolved upstream pull request contains a proposed AVX2 flaw fix, leaving no patched release available.
RustSec advisory database pull request #3151, adding advisories for the pqc_kyber and cosmian_kyber AVX2 key-recovery flaws, was merged.
A broken AVX2 cmov implementation was reported in both crates: it skips Fujisaki-Okamoto implicit rejection during decapsulation and creates a chosen-ciphertext oracle that can enable recovery of reused static secret keys.
pqc_kyber version 0.7.1 was released, becoming the crate's latest release.
The cosmian_kyber crate was last published as version 0.1.0 in January 2023.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
rustsec.org
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcerustsec.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.