CVE-2025-52473: liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52473?
CVE-2025-52473 has been categorized with a severity rating that indicates potential risks associated with secret-dependent branches in the HQC key encapsulation mechanism.
How do I fix CVE-2025-52473?
To mitigate CVE-2025-52473, update to liboqs version 0.14.0 or later, addressing the identified vulnerabilities.
What vulnerabilities are associated with CVE-2025-52473?
CVE-2025-52473 corresponds to vulnerabilities in the HQC key encapsulation mechanism present in the liboqs library.
Which software versions are affected by CVE-2025-52473?
Liboqs versions prior to 0.14.0 are affected by CVE-2025-52473.
What is liboqs in relation to CVE-2025-52473?
Liboqs is a cryptographic library that has vulnerabilities identified in its post-quantum cryptography implementations, specifically related to CVE-2025-52473.