Critical severity9.8NVD Advisory· Published Dec 27, 2021· Updated Jun 17, 2026
CVE-2021-45696
CVE-2021-45696
Description
An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust. Hashes of long messages may be incorrect when the AVX2-accelerated backend is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sha2crates.io | >= 0.9.7, < 0.9.8 | 0.9.8 |
Affected products
3- cpe:2.3:a:sha2_project:sha2:0.9.7:*:*:*:*:rust:*:*
- sha2/sha2description
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-fc7x-2cmc-8j2gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-45696ghsaADVISORY
- raw.githubusercontent.com/rustsec/advisory-db/main/crates/sha2/RUSTSEC-2021-0100.mdnvdThird Party AdvisoryWEB
- rustsec.org/advisories/RUSTSEC-2021-0100.htmlnvdThird Party AdvisoryWEB
- github.com/RustCrypto/hashes/pull/314ghsaWEB
News mentions
0No linked articles in our index yet.