HistoryEditJSON (OSV)

RUSTSEC-2022-0047

Post-Quantum Signature scheme Rainbow level I parametersets broken

Reported
Issued
Package
oqs (crates.io)
Type
Vulnerability
Categories
Aliases
References
Patched
  • >=0.7.2

Description

Ward Beullens found a practical key-recovery attack against Rainbow. The level I parametersets are removed from liboqs starting from version 0.7.2. Find the scientific details in Breaking Rainbow Takes a Weekend on a Laptop.

This means all the oqs::sig::Algorithm::RainbowI* variants are insecure.

Advisory available under CC0-1.0 license.