{"id":"GHSA-hrjv-pf36-jpmr","summary":"oqs's Post-Quantum Key Encapsulation Mechanism SIKE broken","details":"Wouter Castryck and Thomas Decru presented an efficient key recovery attack on the SIDH protocol.\nAs a result, the secret key of SIKEp751 can be recovered in a matter of hours.\nThe SIKE and SIDH schemes will be removed from oqs 0.7.2.\n\n[An efficient key recovery attack on SIDH (preliminary version)](https://eprint.iacr.org/2022/975)\n","aliases":["RUSTSEC-2022-0045"],"modified":"2023-11-08T04:20:13.312979Z","published":"2022-08-18T19:01:15Z","database_specific":{"github_reviewed_at":"2022-08-18T19:01:15Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/open-quantum-safe/liboqs-rust/pull/151"},{"type":"PACKAGE","url":"https://github.com/open-quantum-safe/liboqs-rust"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0045.html"}],"affected":[{"package":{"name":"oqs","ecosystem":"crates.io","purl":"pkg:cargo/oqs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-hrjv-pf36-jpmr/GHSA-hrjv-pf36-jpmr.json"}}],"schema_version":"1.9.0"}