# std.crypto.kem.kyber: mitigate KyberSlash \(\#18316\) · gitcafe/zig

[View on GitCafe](https://git.cafe/gitcafe/zig/commit/21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9)

Repository: [gitcafe/zig](https://git.cafe/gitcafe/zig)

Visibility: public

Requested revision: 21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9

Requested commit: 21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9

Commit: 21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9

Tree: 0fe35730e2a4f73ae29b3c32df8115adcb12eeb8

Author: Frank Denis

Committer: GitHub

## Message

```
std.crypto.kem.kyber: mitigate KyberSlash (#18316)

On some architectures, including AMD Zen CPUs, dividing a secret
by a constant denominator may not be a constant-time operation.

And most Kyber implementations, including ours, could leak the
hamming weight of the shared secret because of this. See:

https://kyberslash.cr.yp.to

Multiplications aren't guaranteed to be constant-time either, but
at least on the CPUs we currently support, it is.
```

## Parents

- [42ddf592dd610dda3371cae2eba63ac3e8502c64](https://git.cafe/gitcafe/zig/commit/42ddf592dd610dda3371cae2eba63ac3e8502c64?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zig/tree/21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9?format=markdown)
