GHSA-h864-m8vm-3xvj: oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken
N/A
CVSS Score
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
-
Published
8/18/2022
Updated
1/7/2023
KEV Status
No
Technology
Rust
Technical Details
CVSS Vector
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| oqs | rust | < 0.7.2 | 0.7.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability specifically affects all Rainbow Level I parametersets (RainbowI* variants) as stated in the advisory. These algorithm variants implement the broken parameters that allow practical key recovery. The file path is inferred from standard Rust crate structure where signature algorithms would be defined in sig.rs. Confidence is high because the advisory explicitly names these variants as insecure and they were removed in the patched version.