CVE-2024-31510

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
24/05/2024
Last modified:
20/08/2025

Description

An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the /pqcrystals-dilithium-standard_ml-dsa-44-ipd_avx2/sign.c component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openquantumsafe:liboqs:0.10.0:-:*:*:*:*:*:*