CVE Feed

    Dashboard / CVE / CVE-2024-36405

    CVE-2024-36405

    liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key encapsulation mechanism when it is compiled with Clang 15-18 for `-Os`, `-O1`, and other compilation options. A proof-of-concept local attack on the reference implementation leaks the entire ML-KEM 512 secret key in ~10 minutes using end-to-end decapsulation timing measurements. The issue has been fixed in version 0.10.1. As a possible workaround, some compiler options may produce vectorized code that does not leak secret information, however relying on these compiler options as a workaround may not be reliable.

    Published:Jun 10, 2024
    Last Modified:Aug 20, 2025
    EPS:Jun 10, 2024
    EPSS Score:0.00343
    CVSS Score:5.9

    Affected Products

    Vendor
    Open Quantum Safe
    Product
    Liboqs
    Vendor
    Openquantumsafe
    Product
    Liboqs

    Exploits

    No exploit reference

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High