CVE Feed

    Dashboard / CVE / CVE-2024-54137

    CVE-2024-54137

    liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data. This results in an incorrect shared secret value being returned when the decapsulation function is called with a malformed ciphertext. This vulnerability is fixed in 0.12.0.

    Published:Dec 6, 2024
    Last Modified:Aug 20, 2025
    EPS:Dec 6, 2024
    EPSS Score:0.00113
    CVSS Score:7.4

    Affected Products

    Vendor
    Open Quantum Safe
    Product
    Liboqs
    Vendor
    Openquantumsafe
    Product
    Liboqs

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High