{"id":"CVE-2024-37880","details":"The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.","modified":"2026-08-12T14:52:17.739643Z","published":"2024-06-10T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37880.json","unresolved_ranges":[{"extracted_events":[{"fixed":"9b8d306"},{"fixed":"18.x"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://news.ycombinator.com/item?id=40577486"},{"type":"WEB","url":"https://pqshield.com/pqshield-plugs-timing-leaks-in-kyber-ml-kem-to-improve-pqc-implementation-maturity/"},{"type":"WEB","url":"https://twitter.com/purnaltoon/status/1797644696568959476"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37880.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37880"},{"type":"FIX","url":"https://github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c"},{"type":"PACKAGE","url":"https://github.com/antoonpurnal/clangover"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pq-crystals/kyber","events":[{"introduced":"0"},{"fixed":"9b8d30698a3e7449aeb34e62339d4176f11e3c6c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37880.json","vanir_signatures_modified":"2026-08-12T14:52:17Z","vanir_signatures":[{"id":"CVE-2024-37880-16c196d2","signature_type":"Line","signature_version":"v1","source":"https://github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c","target":{"file":"ref/verify.h"},"deprecated":false,"digest":{"line_hashes":["129159944488822175469922892442807990041"],"threshold":0.9}},{"digest":{"line_hashes":["234689300167707083092684360083613531595","146167400202682821831380952758195444065","236930179887150445801603796343847781378","132795227996355397657871530656993888564","98085589001609537616281371573502341052","220137936012977417917610474229036188693","230950984777136591460947291073851511222","152441685494613281378637909075275929112","94291155035070951370862928007735827934","301827595347717556978065680018854490571","234954458262773481690591469489954392452","117445256152861512856057429889126623864","140998155976398254487220450403221579936"],"threshold":0.9},"id":"CVE-2024-37880-230f7be1","signature_type":"Line","signature_version":"v1","source":"https://github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c","target":{"file":"ref/poly.c"},"deprecated":false},{"source":"https://github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c","target":{"file":"ref/poly.c","function":"poly_frommsg"},"deprecated":false,"digest":{"length":444,"function_hash":"318988264785853182587844791599630315127"},"id":"CVE-2024-37880-c935abed","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}