Skip to content
SUSE 2026-3420-1 Important liboqs oqs

SUSE 2026-3420-1 Important liboqs oqs

Linuxsecurity LinuxSecurity Advisories July 30, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for liboqs, oqs-provider fixes the following issues: * disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite shows them not working. Updated to 0.16.0: Deprecation notice: * SPHINCS+ was removed in 0.16.0. Security issues: * Fixed uninitialized `encaps_derand` pointer dereference * CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification (bsc#1267007 bsc#1267001) * Fixed Integer underflow in CROSS `crypto_sign_open()` * Fixed incorrect array size when calling `secure_clean` * Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM Significant change: FrodoKEM algorithm change: * Existing FrodoKEM in 0.15.0 was renamed to ephemeral FrodoKEM

## This update for liboqs, oqs-provider fixes the following issues: * disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite shows them not working. Updated to 0.16.0: Deprecation notice: * SPHINCS+ was removed in 0.16.0. Security issues: * Fixed uninitialized `encaps_derand` pointer dereference * CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification (bsc#1267007 bsc#1267001) * Fixed Integer underflow in CROSS `crypto_sign_open()` * Fixed incorrect array size when calling `secure_clean` * Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM Significant change: FrodoKEM algorithm change: * Existing FrodoKEM in 0.15.0 was renamed to ephemeral FrodoKEM

* CVE-2025-52473 ( SUSE ): 5.9

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-52473 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2025-52473 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2025-52473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

* CVE-2026-44518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-44518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-46344 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Announcement ID: SUSE-SU-2026:3420-1 Release Date: 2026-07-30T07:28:37Z Rating: important

Get the latest Linux and open source security news straight to your inbox.