CVE-2024-37880: Pq-Crystals Kyber
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.
Affected products
- Pq-Crystals Kyber: before 2024-06-03 (fixed in 2024-06-03)
Published 2024-06-10. Last modified 2026-06-17.