{"id":"GHSA-hrjv-pf36-jpmr","aliases":["RUSTSEC-2022-0045"],"url":"https://o3.security/vulnerability/GHSA-hrjv-pf36-jpmr","summary":"oqs's Post-Quantum Key Encapsulation Mechanism SIKE broken","details":"Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.\nAs a result, the secret key of SIKEp751 can be recovered in a matter of hours.\nThe SIKE and SIDH schemes will be removed from oqs 0.7.2.\n\n[An efficient key recovery attack on SIDH (preliminary version)](https://eprint.iacr.org/2022/975)\n","published":"2022-08-18T19:01:15Z","modified":"2023-11-08T04:20:13.312979Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"oqs","fixedVersion":"0.7.2"}],"fix":{"url":"https://github.com/open-quantum-safe/liboqs-rust/pull/151","label":"open-quantum-safe/liboqs-rust#151"},"references":[{"type":"WEB","url":"https://github.com/open-quantum-safe/liboqs-rust/pull/151"},{"type":"PACKAGE","url":"https://github.com/open-quantum-safe/liboqs-rust"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0045.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:20:13.312979Z"}}