Headline
GHSA-h864-m8vm-3xvj: oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken
Ward Beullens found a practical key-recovery attack against Rainbow.
The level I parametersets are removed from liboqs starting from version 0.7.2
.
Find the scientific details in Breaking Rainbow Takes a Weekend on a Laptop.
This means all the oqs::sig::Algorithm::RainbowI*
variants are insecure.
oqs’s Post-Quantum Signature scheme Rainbow level I parametersets broken
High severity GitHub Reviewed Published Aug 18, 2022 • Updated Aug 18, 2022