Skip to content

Kyberslash

High
bwesterb published GHSA-p4v8-jgcv-9g75 Dec 30, 2023

Package

cargo safe_pqc_kyber (Rust)

Affected versions

< 0.6.2

Patched versions

0.6.2

Description

Impact

On some platforms, when an attacker can time decapsulation, and in particular when the attacker can forge cipher texts, they can learn (parts of) the secret key.

Does not apply to ephemeral usage, such as when used in the regular way in TLS.

Patches

Patched in 0.6.2.

References

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs