Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-52473

Опубликовано: 10 июл. 2025
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.

An observable discrepancy was found in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 onto -O1, -O2, and beyond. A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10liboqsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-203
https://bugzilla.redhat.com/show_bug.cgi?id=2379349liboqs: liboqs secret-dependent branching in HQC

EPSS

Процентиль: 12%
0.00044
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
около 1 месяца назад

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.

CVSS3: 5.9
debian
около 1 месяца назад

liboqs is a C-language cryptographic library that provides implementat ...

EPSS

Процентиль: 12%
0.00044
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2025-52473