Hello,
We realized that cfb8_decrypt doesn't update the IV correctly when the input is shorter than AES block size. The attached patches should fix it.
Samba is also affected by this and there are similar fixes: https://git.samba.org/?p=gd/nettle;a=commit;h=c9926d319a44858d9bde5c28e37f37... https://git.samba.org/?p=gd/nettle;a=commit;h=a2aa783012ab874eebe79d61500271...
Regards,