CVE-2024-31510: Critical severity liboqs vulnerability
Published May 24, 2024
·Updated
An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the cryptosignsignature parameter in the /pqcrystals-dilithium-standardml-dsa-44-ipdavx2/sign.c component.
Affected Software
2 affected components
Open Quantum Safe liboqs
Openquantumsafe Liboqs=0.10.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 24, 2024
CVE Published
via NVD·03:15 PM
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 2, 2024
Data Sourced
via MITRE·02:03 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31510?
CVE-2024-31510 has a high severity rating due to its potential for remote privilege escalation.
2
How do I fix CVE-2024-31510?
To mitigate CVE-2024-31510, update to the latest version of Open Quantum Safe liboqs that addresses this vulnerability.
3
What systems are affected by CVE-2024-31510?
CVE-2024-31510 affects the Open Quantum Safe liboqs version 10.0 and potentially earlier versions.
4
Can CVE-2024-31510 be exploited remotely?
Yes, CVE-2024-31510 can be exploited remotely, allowing attackers to escalate privileges.
5
What components of Open Quantum Safe liboqs are implicated in CVE-2024-31510?
CVE-2024-31510 specifically affects the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.