{"id":"GHSA-p4v8-jgcv-9g75","aliases":[],"url":"https://o3.security/vulnerability/GHSA-p4v8-jgcv-9g75","summary":"safe_pqc_kyber leaks parts of secret keys","details":"### Impact\nOn some platforms, when an attacker can time decapsulation, and in particular when the attacker can forge cipher texts, they can learn (parts of) the secret key.\n\nDoes not apply to ephemeral usage, such as when used in the regular way in TLS.\n\n### Patches\nPatched in 0.6.2.\n\n\n### References\n- [kyberslash.cr.yp.to](https://kyberslash.cr.yp.to)","published":"2024-01-03T21:40:45Z","modified":"2024-01-03T21:40:45Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"safe_pqc_kyber","fixedVersion":"0.6.2"}],"fix":{"url":"https://github.com/bwesterb/argyle-kyber/commit/b5c6ad13f4eece80e59c6ebeafd787ba1519f5f6","label":"bwesterb/argyle-kyber@b5c6ad1"},"references":[{"type":"WEB","url":"https://github.com/bwesterb/argyle-kyber/security/advisories/GHSA-p4v8-jgcv-9g75"},{"type":"WEB","url":"https://github.com/bwesterb/argyle-kyber/commit/b5c6ad13f4eece80e59c6ebeafd787ba1519f5f6"},{"type":"PACKAGE","url":"https://github.com/bwesterb/argyle-kyber"},{"type":"WEB","url":"https://kyberslash.cr.yp.to"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-01-03T21:40:45Z"}}