CVE-2025-29779 affects Post-Quantum Secure Feldman's Verifiable Secret Sharing versions 0.8.0b2 and prior, specifically its Python implementation of Feldman's VSS. The vulnerability lies in the insecure fault injection mitigation within the secure_redundant_execution function, which fails to provide true isolation or robust timing protection, making it susceptible to bypass. This is a Medium severity vulnerability (CVSS 5.4) with a physical attack vector and high attack complexity. A successful fault injection attack could allow an attacker with physical access to extract secret coefficients, force acceptance of invalid shares, or manipulate commitment verification, undermining the scheme's security guarantees. As of publication, there are no known exploits in the wild, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. While no patched versions exist, mitigations include physical security controls and increasing redundancy.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DavidOsipov | PostQuantum-Feldman-VSS | <= 0.8.0b2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.