The KyberSlash vulnerability and the crystals-go library: A retrospective story
ID: 11688bc3-3b44-5e10-9a12-f9f2125a749b
STIX ID: report--11688bc3-3b44-5e10-9a12-f9f2125a749b
Feed Name: Kudelski Security
This blog post describes how the unmaintained Kudelski Security open-source project crystals-go was found to be vulnerable to the KyberSlash timing side‑channel attacks affecting Kyber implementations. The authors explain the technical root cause (variable-time division by a constant), detail how they implemented constant-time integer-division approximations to patch KyberSlash1 and KyberSlash2 across legacy parameters, and describe the communication response: updating the README, issuing a security advisory, patching the code, and archiving the repository to prevent misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
