rustpq / pqcrypto

Rust Post-Quantum cryptography
226 stars 41 forks source link

Compiler-introduced timing leak in Kyber reference implementation #61

Open antoonpurnal opened 4 months ago

antoonpurnal commented 4 months ago

This is a heads-up about a compiler-introduced timing side-channel security issue in PQClean: https://github.com/PQClean/PQClean/issues/556

Thanks to the help of Peter Schwabe, the pqcrystals/kyber upstream already has a fix available for this issue at https://github.com/pq-crystals/kyber/commit/9b8d30698a3e7449aeb34e62339d4176f11e3c6c