From the paper:
“At least four Dilithium software vulnerabilities have been announced so far, including an identical vulnerability in each of the two official Dilithium 1.0 implementations and two different vulnerabilities in a “verified” implementation of Dilithium 3.4, also known as ML-DSA. However, there do not appear to have been any demos showing exploitability of any of these vulnerabilities.
This paper shows that a small change in ML-DSA software creates an ML-DSA version of the Dilithium 1.0 software vulnerability, can occur by accident as in the original vulnerability, interoperates with authentic ML-DSA, passes typical tests, and is exploitable in 1 second on 1 laptop core. This paper provides an open-source attack demo that inspects a public key and two signatures, obtains an equivalent secret key, and uses this key to rapidly forge signatures on attacker-chosen messages. […]”
- This paper is also discussed in Detail here: https://postquantum.com/security-pqc/bernstein-exploiting-mldsa-bugs/
- The research paper by Daniel J. Bernstein is available here: https://cr.yp.to/papers/mldsa-20260601.pdf
- Foto von Markus Spiske auf Unsplash