Qubit Guard

ML-KEM is mathematically sound. The library shipping it wasn’t — and for eight months, nobody noticed

ML-KEM is mathematically sound. The library shipping it wasn’t — and for eight months, nobody noticed.

In August, researchers (including Anthropic’s Nicholas Carlini) disclosed two implementation flaws in wolfSSL’s hand-optimized ML-KEM decapsulation code. Both are now patched, but the mechanism deserves every CISO’s attention:

In August, researchers (including Anthropic’s Nicholas Carlini) disclosed two implementation flaws…” (which is already done well in the text!

𝗧𝗵𝗲 𝗯𝘂𝗴: wolfSSL’s SIMD assembly for the Fujisaki–Okamoto ciphertext-comparison check skipped bytes — the AVX2 path verified only 1,536 of 1,568 bytes on ML-KEM-1024; the ARM64 NEON path missed roughly half.

𝗧𝗵𝗲 𝗰𝗼𝗻𝘀𝗲𝗾𝘂𝗲𝗻𝗰𝗲: those skipped bytes carry decryption noise that’s a linear function of the secret key. An attacker who can submit malformed ciphertexts and observe decapsulation behavior can solve for that key via ordinary least squares — no lattice reduction needed. Reported success rate: 98%+, in a few hundred chosen ciphertexts.

𝗧𝗵𝗲 𝘀𝗰𝗼𝗽𝗲: CVE-2026-10097 (CVSS 8.3) and CVE-2026-6330 affected wolfSSL 5.7.0–5.9.1, fixed in 5.9.2. Static-key deployments carried real risk; ephemeral TLS sessions saw only a weaker distinguishing break.

𝗧𝗵𝗲 𝗹𝗲𝘀𝘀𝗼𝗻: “NIST-standardized algorithm” and “correctly implemented algorithm” are two separate claims. The FO comparison step is now a first-order audit target for anyone reviewing PQC libraries in production.

𝗕𝗼𝘁𝘁𝗼𝗺 𝗟𝗶𝗻𝗲: Standardization solved the math problem. It didn’t solve the implementation problem — that’s on your team, your vendors, and whoever is auditing the crypto libraries actually running in your stack.

Is implementation-level review part of your PQC migration plan, or are you trusting library defaults?

#PostQuantumCryptography #PQC #Cybersecurity #CryptoAgility #MLKEM #CISO #QuantumSafe #InfoSec #TLS #NIST

Sources:
– Incomplete Ciphertext Comparison in ML-KEM: From an IND-CCA2 Break to Key Recovery (IACR ePrint 2026/1682): https://www.google.com/url?q=https://eprint.iacr.org/2026/1682&source=gmail&ust=1790683466334000&sa=E

– CVE-2026-10097 record: https://www.google.com/url?q=https://app.opencve.io/cve/CVE-2026-10097&source=gmail&ust=1790683466334000&sa=E

– wolfSSL ML-KEM Key Recovery Bug analysis: https://www.google.com/url?q=https://postquantum.com/security-pqc/wolfssl-mlkem-key-recovery-fo-check/&source=gmail&ust=1790683466334000&sa=E

Leave a Reply

You must be logged in to post a comment.

Qubit Guard messenger is helping businesses and larger networks that manage huge user base by providing a clear structure of conversations

Qubit Guard messenger is helping businesses and larger networks that manage huge user base by providing a clear structure of conversations