An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.
History

Tue, 17 Jun 2025 06:30:00 +0000

Type Values Removed Values Added
References

Wed, 28 May 2025 17:00:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 02:45:00 +0000

Type Values Removed Values Added
Title liboqs: leakable Secret Key of ML-DSA via Rowhammer
Weaknesses CWE-1256
References
Metrics threat_severity

None

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-05-24T14:14:31.086Z

Updated: 2025-02-13T15:47:51.714Z

Reserved: 2024-04-05T00:00:00.000Z

Link: CVE-2024-31510

cve-icon Vulnrichment

Updated: 2024-08-02T01:52:57.290Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-24T15:15:23.587

Modified: 2024-11-21T09:13:40.523

Link: CVE-2024-31510

cve-icon Redhat

Severity : Important

Publid Date: 2024-05-24T00:00:00Z

Links: CVE-2024-31510 - Bugzilla