VYPR
High severity7.5NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026

CVE-2024-37880

CVE-2024-37880

Description

The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Pq Crystals/kyber2 versions
    cpe:2.3:a:pq-crystals:kyber:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pq-crystals:kyber:*:*:*:*:*:*:*:*range: <2024-06-03
    • (no CPE)range: <9b8d306
  • Kyber/Kyber reference implementationdescription
  • Llvm/Clangllm-fuzzy
    Range: <=18.x

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.