Bug 2369500 (CVE-2025-48946)
| Summary: | CVE-2025-48946 liboqs: liboqs affected by theoretical design flaw in HQC | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw in the HQC algorithm family in liboqs. Under specific conditions, an attacker who can capture an encrypted exchange can recover the clear text. There is currently no patch as the algorithm specification is the core issue. The HQC team is working on an updated specification. Users should follow the HQC mailing list for updates.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2369518, 2369517 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-05-30 20:01:43 UTC
|