wycheproof-ml-dsa-missing-reduction
ML-DSA: Missing reduction
A verifier that omits a modular reduction in the verification NTT path lets the inverse-NTT butterfly overflow a 32-bit accumulator and wrongly accepts/rejects this vector. See https://eprint.iacr.org/2026/1032.
REJECT
Your service should reject this one.
Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.
A verifier that omits a modular reduction in the verification NTT path lets the inverse-NTT butterfly overflow a 32-bit accumulator and wrongly accepts/rejects this vector. See https://eprint.iacr.org/2026/1032. Demonstrated by 2 test vectors in Project Wycheproof.
Provenance
- Kind
- normativeA specification clause requires this. Failing it is non-conformance, not opinion.
- Source
- wycheproof
- Clause
- FIPS 204
- CVE
- none
- Weakness
- none
Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.