Bug 1226468 (CVE-2024-37305) - VUL-0: CVE-2024-37305: oqs-provider: buffer overflow in deserialization of hybrid keys and signatures
Summary: VUL-0: CVE-2024-37305: oqs-provider: buffer overflow in deserialization of hy...
Status: NEW
Alias: CVE-2024-37305
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Marcus Meissner
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/411146/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-37305:8.2:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-18 08:22 UTC by SMASH SMASH
Modified: 2024-07-16 19:52 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-06-18 08:22:25 UTC
oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid (traditional + post-quantum) keys and signatures. Unchecked length values are later used for memory reads and writes; malformed input can lead to crashes or information leakage. Handling of plain/non-hybrid PQ key operation is not affected. This issue has been patched in in v0.6.1. All users are advised to upgrade. There are no workarounds for this issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-37305
https://www.cve.org/CVERecord?id=CVE-2024-37305
https://github.com/open-quantum-safe/oqs-provider/pull/416
https://github.com/open-quantum-safe/oqs-provider/security/advisories/GHSA-pqvr-5cr8-v6fx
https://bugzilla.redhat.com/show_bug.cgi?id=2292772
Comment 1 Andrea Mattiazzo 2024-06-18 08:28:41 UTC
Tracking as affected:
- openSUSE:Backports:SLE-15-SP5/oqs-provider  0.3.0
- openSUSE:Factory/oqs-provider               0.6.0
- SUSE:ALP:Source:Standard:1.0/oqs-provider   0.5.0
- SUSE:SLE-15-SP6:Update/oqs-provider         0.5.0
- SUSE:SLFO:Main/oqs-provider                 0.6.0
Comment 2 OBSbugzilla Bot 2024-06-18 13:45:03 UTC
This is an autogenerated message for OBS integration:
This bug (1226468) was mentioned in
https://build.opensuse.org/request/show/1181501 Factory / oqs-provider