liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data. This results in an incorrect shared secret value being returned when the decapsulation function is called with a malformed ciphertext. This vulnerability is fixed in 0.12.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-200"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54137.json"
}{
"cpe": "cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.12.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-54137.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "300864988974983712315002864430706282974",
"length": 1572
},
"id": "CVE-2024-54137-0c3dd5f8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-256_clean/kem.c",
"function": "PQCLEAN_HQC256_CLEAN_crypto_kem_dec"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "300864988974983712315002864430706282974",
"length": 1572
},
"id": "CVE-2024-54137-3c828ac9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-128_clean/kem.c",
"function": "PQCLEAN_HQC128_CLEAN_crypto_kem_dec"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"162838030810147607035953070913432789505",
"333297849662702312561101928865212509870",
"252058898546657984130441420900830600067",
"260904884539454881735285585661244766564",
"254555029910203932856613551384883362760",
"271312578628554478085567115969199320682",
"26160802113611138012078031025597351548",
"134195261742106219160838665828927763669",
"133382066553412584196295343302560391133",
"241479900929718297550317829903512833679"
],
"threshold": 0.9
},
"id": "CVE-2024-54137-7198f4cb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-128_clean/kem.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "300864988974983712315002864430706282974",
"length": 1572
},
"id": "CVE-2024-54137-88d0baee",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-192_clean/kem.c",
"function": "PQCLEAN_HQC192_CLEAN_crypto_kem_dec"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"162838030810147607035953070913432789505",
"333297849662702312561101928865212509870",
"252058898546657984130441420900830600067",
"260904884539454881735285585661244766564",
"27271710052186439330568682823322690858",
"290522601002965717562908241756726981664",
"85920923524750794994809423375729517901",
"134195261742106219160838665828927763669",
"268978289895623875880274538811573817214",
"198720181789611750031685338872275396682"
],
"threshold": 0.9
},
"id": "CVE-2024-54137-9f94e198",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-256_clean/kem.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"162838030810147607035953070913432789505",
"333297849662702312561101928865212509870",
"252058898546657984130441420900830600067",
"260904884539454881735285585661244766564",
"86343765712182988309801327710656902166",
"279734377702258196943667699271756842887",
"266718170927845913102485241910242087000",
"134195261742106219160838665828927763669",
"302925322713517585937636764424140972494",
"146729734407520018998222784322301372944"
],
"threshold": 0.9
},
"id": "CVE-2024-54137-b7063a7f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open-quantum-safe/liboqs/commit/cce1bfde4e52c524b087b9687020d283fbde0f24",
"target": {
"file": "src/kem/hqc/pqclean_hqc-192_clean/kem.c"
}
}
]
"2026-08-12T15:13:10Z"