GHSA-hvh4-5qr6-3v7r
HIGHkyber512, kyber768, and kyber1024 on Mac OS \(or when compiled with clang\) only: An attacker able to submit many decapsulation requests against a single private key, and to gain timing information about the decapsulation, could recover the private key. Proof-of-concept exploit exists for a local attacker.
- Affected
- >= 0.0.4, <= 0.0.6.2
- Fixed in
- not stated
- Weakness
- CWE-385
- Published
- 2024-06-05
- Source
- github