PT-2025-23341 · Liboqs · Liboqs
Deirdre Connolly
+1
·
Published
2025-05-30
·
Updated
2025-08-25
·
CVE-2025-48946
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
liboqs versions prior to 0.13.0
Description
The issue is related to a theoretical design flaw in the HQC algorithm, which is implemented in liboqs. This flaw can lead to large numbers of malformed ciphertexts sharing the same implicit rejection value. Although no concrete attack on the algorithm is currently known, users of HQC must exercise extra caution when using the algorithm in protocols involving key derivation. The HQC algorithm does not provide the same security guarantees as other algorithms like Kyber or ML-KEM.
Recommendations
For liboqs versions prior to 0.13.0, consider disabling the HQC algorithm to minimize potential risks until an updated algorithm specification is released by the HQC team and implemented in liboqs.
At the moment, there is no information about a newer version that contains a fix for this vulnerability, but HQC is disabled by default in liboqs starting from version 0.13.0.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liboqs