openSUSE-SU-2026:21634-1: moderate: Security update for liboqs
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for liboqs
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21634-1
Rating: moderate
References:
* bsc#1215751
* bsc#1246301
* bsc#1267001
* bsc#1267007
Cross-References:
* CVE-2025-52473
* CVE-2026-44518
* CVE-2026-46344
CVSS scores:
* CVE-2025-52473 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-52473 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46344 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed.
Description:
This update for liboqs fixes the following issues:
Changes in liboqs:
Updated to 0.16.0:
Deprecation notice:
- SPHINCS+ was removed in 0.16.0.
Security issues:
- Fixed uninitialized `encaps_derand` pointer dereference
- CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification
(bsc#1267007 bsc#1267001)
- Fixed Integer underflow in CROSS `crypto_sign_open()`
- Fixed incorrect array size when calling `secure_clean`
- Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM
Significant change:
FrodoKEM algorithm change:
* Existing FrodoKEM in 0.15.0 was renamed to ephemeral
FrodoKEM (`KEM_efrodokem_<640|976|1344>_<aes|shake>`), and
the salted variant of FrodoKEM was added under the prior names
(`KEM_frodokem_<640|976|1344>_<aes|shake>`).
Ephemeral FrodoKEM is recommended for applications
where each keypair will encapsulate only a small number
of shared secrets and ciphertexts. Standard (salted)
FrodoKEM is recommended for applications where each keypair
is expected to encapsulate large number of ciphertexts. Please consult
[upstream](https://github.com/microsoft/PQCrypto-LWEKE/#frodokem-learning-with-errors-key-encapsulation)
for more details.
* mldsa-native integration:
mldsa-native is a secure, fast, and portable C90 implementation of the
ML-DSA post-quantum signature standard. It also includes optimized
builds for x86_64 and aarch64. It is now the default implementation
behind `SIG_ml_dsa_<44|65|87>`.
* Updated HQC implementation:
The HQC implementations in liboqs were updated to 20250822
spec. Its upstream switched from PQClean to the [official
repo](https://gitlab.com/pqc-hqc/hqc). `KEM_hqc_<1|3|5>` is now enabled
by default.
* MQOM integration and memory-optimized build flag:
MQOM is a third-round candidate in NIST's Additional Digital
Signatures for the PQC Standardization Process. Portable,
x86_64-optimized, and memory-optimized implementations were
integrate into liboqs under `OQS_ENABLE_SIG_MQOM`.
* OpenSSH implementation of NTRU Prime:
A public-domain OpenSSH implementation of NTRUPrime761
replaced the PQClean implementation as the default backend for
`KEM_ntruprime_sntrup761`.
Bug fixes:
- Fixed incremental absorption bug in AVX512VL SHA3-512 [#2442](https://github.com/open-quantum-safe/liboqs/pull/2442)
- Implemented fallback for when `EVP_DigestSqueeze` is unavailable [#2433](https://github.com/open-quantum-safe/liboqs/pull/2433)
- Added API for detecting stateful signature support at runtime [#2434](https://github.com/open-quantum-safe/liboqs/pull/2434)
- Fixed missing initialization and indexing bug in LMS [#2416](https://github.com/open-quantum-safe/liboqs/pull/2416)
- Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO [#2403](https://github.com/open-quantum-safe/liboqs/pull/2403)
- Limited pytest parallelism to prevent memory exhaustion in constrained environment [#2397](https://github.com/open-quantum-safe/liboqs/pull/2397)
- Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains [#2396](https://github.com/open-quantum-safe/liboqs/pull/2396)
- Tightened Windows compiler detection [#2394](https://github.com/open-quantum-safe/liboqs/pull/2394)
- Fixed mismatched macros in LMS [#2379](https://github.com/open-quantum-safe/liboqs/pull/2379)
- Made fuzzers tolerant to disabled algorithms [#2359](https://github.com/open-quantum-safe/liboqs/pull/2359)
- Removed inlined exponentiation in CROSS-RSDPG-1 [#2357](https://github.com/open-quantum-safe/liboqs/pull/2357)
- Fixed incorrect arg register update in AVX512 Keccak [#2330](https://github.com/open-quantum-safe/liboqs/pull/2330)
- Update to 0.15.0:
* Significant changes:
- Integrated SLH-DSA implementation from pq-code-package/slhdsa-c
- SLH-DSA ACVP tests (#2237)
- Integrate SLH-DSA-C Library (#2175)
- Added NTRU back (#2176)
- Removed all Dilithium implementations (#2275)
- Replaced SPHINCS+ with SLH-DSA for CMake build option
OQS_ALGS_ENABLED=STD (#2290)
- Updated CROSS to version 2.2 (#2247)
- Included DeriveEncapsulation functionality (#2221)
- Integrated ML-KEM implementation from ICICLE-PQC (#2216)
* Bug fixes:
- Fixed erroneously disabled LMS variants with build flag
OQS_ENABLE_SIG_STFL_LMS (#2310)
- Fixed incorrect import in OV-III-pkc_skc (#2299)
- Fixed incorrect actual signature length in signature full-cycle
speed test (#2293)
- Fixed ICICLE ML-KEM integration (#2288)
- Disabled strict aliasing on SPHINCS+-SHAKE (#2264)
- Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)
- Changed 64 bit add to 32 bit add to wrap on 32 bit counter for
AES-CTR AES-NI implementation (#2252)
- Improved random number generator security (#2225)
- Added Classic McEliece sanitization patch (#2218)
* Miscellaneous:
- Deprecated noregress scripts (#2295)
- Updated no-pass explanation for constant-time testing (#2294)
- Re-enabled all ACVP tests (#2283)
- Updated license info for ML-KEM (#2250)
- Added Poutine SASL (#2213)
- Updated ACVP to 1.1.0.40 (#2172)
- Switched to dev mode for 0.14.1 (#2199)
* Deprecation notice: liboqs 0.15.0 is the last version to officially
support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and
replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.
Updated to 0.14.0:
* Key encapsulation mechanisms:
- HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.
- ML-KEM: Updated the default ML-KEM implementation to [PQCP's mlkem-native v1.0.0](https://github.com/pq-code-package/mlkem-native/releases/tag/v1.0.0).
* Digital signature schemes:
- New API: added an API function to check if a signature scheme supports signing with a context string.
- SNOVA: added [SNOVA](https://snova.pqclab.org/) from NIST Additional Signature Schemes Round 2.
* Other changes:
- Added an AVX512VL-optimized backend for SHA3.
- Improved memory management throughout the codebase.
- CVE-2025-52473: Disabled compiler optimizations for HQC to avoid
secret-dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang
from from the University of Melbourne and the Max Planck Institute
for Security and Privacy for identifying the issue. (bsc#1246301)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1493=1
Package List:
- openSUSE Leap 16.0:
liboqs-devel-0.16.0-160000.1.1
liboqs9-0.16.0-160000.1.1
oqs-provider-0.11.0.32-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2025-52473.html
* https://www.suse.com/security/cve/CVE-2026-44518.html
* https://www.suse.com/security/cve/CVE-2026-46344.html