std.crypto.kem.kyber: mitigate KyberSlash (#18316)

On some architectures, including AMD Zen CPUs, dividing a secret
by a constant denominator may not be a constant-time operation.

And most Kyber implementations, including ours, could leak the
hamming weight of the shared secret because of this. See:

https://kyberslash.cr.yp.to

Multiplications aren't guaranteed to be constant-time either, but
at least on the CPUs we currently support, it is.
21ae64852aFrank Denis committed on 12/22/2023, 3:57:16 PM· committed by GitHubparent42ddf59
1 file changedLine totals unavailable