Critical Vulnerabilities in liboqs and oqs-provider Affecting openSUSE Systems

Critical Vulnerabilities in liboqs and oqs-provider Affecting openSUSE Systems

First seen 30 Jul 2026, 18:51 UTC Linuxsecurity 95% similarity 70.5

Article Content

Browse articles
ThreatCluster

On July 30, 2026, an important update was released for liboqs and oqs-provider addressing multiple security vulnerabilities. The update disables KEM_HQC and SIG_MQOM on s390x due to failures in the testsuite. Significant changes include the removal of SPHINCS+ in version 0.16.0 and fixes for CVE-2026-46344 and CVE-2026-44518, which involve out-of-bounds reads in signature verification. Other fixes include an uninitialized pointer dereference and integer underflow in the CROSS `crypto_sign_open()` function. The FrodoKEM algorithm was also updated, renaming the existing version to ephemeral FrodoKEM. Users are advised to apply the patches immediately to mitigate risks. The vulnerabilities could potentially lead to unauthorized access or system compromise if exploited.

Key Points: • Critical vulnerabilities in liboqs and oqs-provider require immediate patching. • CVE-2026-46344 and CVE-2026-44518 involve serious security flaws in signature verification. • The update includes significant changes to the FrodoKEM algorithm and disables certain KEMs on s390x.

ThreatCluster AI How this analysis works

Timeline

2025-07-10
CVE-2025-52473 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-29
CVE-2026-46344 published
An out-of-bounds read vulnerability in XMSS/XMSS^MT signature verification was disclosed.
Linuxsecurity
2026-05-29
CVE-2026-44518 published
An integer underflow vulnerability in CROSS `crypto_sign_open()` was disclosed.
Linuxsecurity
2026-07-30
Patch released for liboqs and oqs-provider
SUSE released an important update addressing multiple vulnerabilities and disabling certain KEMs on s390x.
Linuxsecurity

Community

Browse all →