openSUSE-SU-2026:21634-1: moderate: Security update for liboqs

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for liboqs
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21634-1
Rating: moderate
References:

  * bsc#1215751
  * bsc#1246301
  * bsc#1267001
  * bsc#1267007



Cross-References:

  * CVE-2025-52473
  * CVE-2026-44518
  * CVE-2026-46344



CVSS scores:

  * CVE-2025-52473 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2025-52473 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-44518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-46344 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed.

Description:

This update for liboqs fixes the following issues:

Changes in liboqs:

Updated to 0.16.0:

  Deprecation notice:

  - SPHINCS+ was removed in 0.16.0.

  Security issues:

  - Fixed uninitialized `encaps_derand` pointer dereference
  - CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification
    (bsc#1267007 bsc#1267001)
  - Fixed Integer underflow in CROSS `crypto_sign_open()`
  - Fixed incorrect array size when calling `secure_clean`
  - Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM

  Significant change:

  FrodoKEM algorithm change:

  * Existing FrodoKEM in 0.15.0 was renamed to ephemeral
    FrodoKEM (`KEM_efrodokem_<640|976|1344>_<aes|shake>`), and
    the salted variant of FrodoKEM was added under the prior names
    (`KEM_frodokem_<640|976|1344>_<aes|shake>`).

    Ephemeral FrodoKEM is recommended for applications
    where each keypair will encapsulate only a small number
    of shared secrets and ciphertexts. Standard (salted)
    FrodoKEM is recommended for applications where each keypair
    is expected to encapsulate large number of ciphertexts. Please consult
    [upstream](https://github.com/microsoft/PQCrypto-LWEKE/#frodokem-learning-with-errors-key-encapsulation)
    for more details.

  * mldsa-native integration:

    mldsa-native is a secure, fast, and portable C90 implementation of the
    ML-DSA post-quantum signature standard. It also includes optimized
    builds for x86_64 and aarch64. It is now the default implementation
    behind `SIG_ml_dsa_<44|65|87>`.

  * Updated HQC implementation:

    The HQC implementations in liboqs were updated to 20250822
    spec. Its upstream switched from PQClean to the [official
    repo](https://gitlab.com/pqc-hqc/hqc). `KEM_hqc_<1|3|5>` is now enabled
    by default.

  * MQOM integration and memory-optimized build flag:

    MQOM is a third-round candidate in NIST's Additional Digital
    Signatures for the PQC Standardization Process. Portable,
    x86_64-optimized, and memory-optimized implementations were
    integrate into liboqs under `OQS_ENABLE_SIG_MQOM`.


  * OpenSSH implementation of NTRU Prime:

    A public-domain OpenSSH implementation of NTRUPrime761
    replaced the PQClean implementation as the default backend for
    `KEM_ntruprime_sntrup761`.

  Bug fixes:

  - Fixed incremental absorption bug in AVX512VL SHA3-512 [#2442](https://github.com/open-quantum-safe/liboqs/pull/2442)
  - Implemented fallback for when `EVP_DigestSqueeze` is unavailable [#2433](https://github.com/open-quantum-safe/liboqs/pull/2433)
  - Added API for detecting stateful signature support at runtime [#2434](https://github.com/open-quantum-safe/liboqs/pull/2434)
  - Fixed missing initialization and indexing bug in LMS [#2416](https://github.com/open-quantum-safe/liboqs/pull/2416)
  - Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO [#2403](https://github.com/open-quantum-safe/liboqs/pull/2403)
  - Limited pytest parallelism to prevent memory exhaustion in constrained environment [#2397](https://github.com/open-quantum-safe/liboqs/pull/2397)
  - Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains [#2396](https://github.com/open-quantum-safe/liboqs/pull/2396)
  - Tightened Windows compiler detection [#2394](https://github.com/open-quantum-safe/liboqs/pull/2394)
  - Fixed mismatched macros in LMS [#2379](https://github.com/open-quantum-safe/liboqs/pull/2379)
  - Made fuzzers tolerant to disabled algorithms [#2359](https://github.com/open-quantum-safe/liboqs/pull/2359)
  - Removed inlined exponentiation in CROSS-RSDPG-1 [#2357](https://github.com/open-quantum-safe/liboqs/pull/2357)
  - Fixed incorrect arg register update in AVX512 Keccak [#2330](https://github.com/open-quantum-safe/liboqs/pull/2330)

- Update to 0.15.0:
  * Significant changes:
    - Integrated SLH-DSA implementation from pq-code-package/slhdsa-c
    - SLH-DSA ACVP tests (#2237)
    - Integrate SLH-DSA-C Library (#2175)
    - Added NTRU back (#2176)
    - Removed all Dilithium implementations (#2275)
    - Replaced SPHINCS+ with SLH-DSA for CMake build option
      OQS_ALGS_ENABLED=STD (#2290)
    - Updated CROSS to version 2.2 (#2247)
    - Included DeriveEncapsulation functionality (#2221)
    - Integrated ML-KEM implementation from ICICLE-PQC (#2216)
  * Bug fixes:
    - Fixed erroneously disabled LMS variants with build flag
      OQS_ENABLE_SIG_STFL_LMS (#2310)
    - Fixed incorrect import in OV-III-pkc_skc (#2299)
    - Fixed incorrect actual signature length in signature full-cycle
      speed test (#2293)
    - Fixed ICICLE ML-KEM integration (#2288)
    - Disabled strict aliasing on SPHINCS+-SHAKE (#2264)
    - Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)
    - Changed 64 bit add to 32 bit add to wrap on 32 bit counter for
      AES-CTR AES-NI implementation (#2252)
    - Improved random number generator security (#2225)
    - Added Classic McEliece sanitization patch (#2218)
  * Miscellaneous:
    - Deprecated noregress scripts (#2295)
    - Updated no-pass explanation for constant-time testing (#2294)
    - Re-enabled all ACVP tests (#2283)
    - Updated license info for ML-KEM (#2250)
    - Added Poutine SASL (#2213)
    - Updated ACVP to 1.1.0.40 (#2172)
    - Switched to dev mode for 0.14.1 (#2199)
  * Deprecation notice: liboqs 0.15.0 is the last version to officially
    support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and
    replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.

Updated to 0.14.0:

  * Key encapsulation mechanisms:
    - HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.
    - ML-KEM: Updated the default ML-KEM implementation to [PQCP's mlkem-native v1.0.0](https://github.com/pq-code-package/mlkem-native/releases/tag/v1.0.0).
  * Digital signature schemes:
    - New API: added an API function to check if a signature scheme supports signing with a context string.
    - SNOVA: added [SNOVA](https://snova.pqclab.org/) from NIST Additional Signature Schemes Round 2.

  * Other changes:
     - Added an AVX512VL-optimized backend for SHA3.
     - Improved memory management throughout the codebase.

- CVE-2025-52473: Disabled compiler optimizations for HQC to avoid
  secret-dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang
  from from the University of Melbourne and the Max Planck Institute
  for Security and Privacy for identifying the issue. (bsc#1246301)


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1493=1

Package List:

- openSUSE Leap 16.0:

  liboqs-devel-0.16.0-160000.1.1
  liboqs9-0.16.0-160000.1.1
  oqs-provider-0.11.0.32-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2025-52473.html
  * https://www.suse.com/security/cve/CVE-2026-44518.html
  * https://www.suse.com/security/cve/CVE-2026-46344.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.