oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid (traditional + post-quantum) keys and signatures. Unchecked length values are later used for memory reads and writes; malformed input can lead to crashes or information leakage. Handling of plain/non-hybrid PQ key operation is not affected. This issue has been patched in in v0.6.1. All users are advised to upgrade. There are no workarounds for this issue.
History

Fri, 30 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-06-17T19:42:22.091Z

Updated: 2024-08-02T03:50:56.102Z

Reserved: 2024-06-05T20:10:46.497Z

Link: CVE-2024-37305

cve-icon Vulnrichment

Updated: 2024-06-18T13:35:00.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-17T20:15:12.880

Modified: 2024-06-20T12:44:22.977

Link: CVE-2024-37305

cve-icon Redhat

Severity : Important

Publid Date: 2024-06-17T00:00:00Z

Links: CVE-2024-37305 - Bugzilla