CVE-2026-10097: ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
wolfSSL's AVX2-optimized ML-KEM implementation (mlkemcmpavx2) compares only 1536 of the 1568 ciphertext bytes during the Fujisaki-Okamoto re-encryption check in ML-KEM-1024 decapsulation. Ciphertexts that differ from the expected re-encryption solely in bytes 1536-1567 bypass implicit rejection and are accepted as valid, breaking IND-CCA2 security. An attacker able to submit chosen ciphertexts to a decapsulation oracle that uses a static ML-KEM-1024 key, and to observe whether the genuine shared secret or the implicit-rejection secret was produced, can use this as a plaintext-checking oracle to recover the private key. A proof of concept recovered a full ML-KEM-1024 private key with approximately 98% success using roughly 350 chosen ciphertexts. The flaw is a deterministic logic error and does not rely on timing measurements.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10097?
The severity of CVE-2026-10097 is classified as high with a score of 8.3.
What is CVE-2026-10097 about?
CVE-2026-10097 describes an issue in wolfSSL's ML-KEM implementation where incomplete ciphertext comparison can lead to IND-CCA2 breaks and private key recovery.
How do I fix CVE-2026-10097?
To address CVE-2026-10097, you should update to a patched version of wolfSSL that resolves the incomplete ciphertext comparison issue.
What software is affected by CVE-2026-10097?
CVE-2026-10097 affects wolfSSL's AVX2-optimized ML-KEM implementation.
What are the potential impacts of CVE-2026-10097?
The potential impacts of CVE-2026-10097 include the ability for attackers to recover static private keys due to a flaw in ciphertext comparison.