Linuxsecurity
Critical Vulnerabilities in liboqs and oqs-provider Affecting openSUSE Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 30, 2026, an important update was released for liboqs and oqs-provider addressing multiple security vulnerabilities. The update disables KEM_HQC and SIG_MQOM on s390x due to failures in the testsuite. Significant changes include the removal of SPHINCS+ in version 0.16.0 and fixes for CVE-2026-46344 and CVE-2026-44518, which involve out-of-bounds reads in signature verification. Other fixes include an uninitialized pointer dereference and integer underflow in the CROSS `crypto_sign_open()` function. The FrodoKEM algorithm was also updated, renaming the existing version to ephemeral FrodoKEM. Users are advised to apply the patches immediately to mitigate risks. The vulnerabilities could potentially lead to unauthorized access or system compromise if exploited.
Key Points: • Critical vulnerabilities in liboqs and oqs-provider require immediate patching. • CVE-2026-46344 and CVE-2026-44518 involve serious security flaws in signature verification. • The update includes significant changes to the FrodoKEM algorithm and disables certain KEMs on s390x.