Unrated severityNVD Advisory· Published Jul 10, 2025· Updated Jul 10, 2025
liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20
CVE-2025-52473
Description
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.
Affected products
2- Range: >=0.14.0?
- open-quantum-safe/liboqsv5Range: < 0.14.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/open-quantum-safe/liboqs/commit/4215362acbf69b88fe1777c4c052f154e29f9897mitrex_refsource_MISC
- github.com/open-quantum-safe/liboqs/security/advisories/GHSA-qq3m-rq9v-jfgmmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.