Описание
Security update for liboqs, oqs-provider
This update for liboqs, oqs-provider fixes the following issues:
- disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite shows them not working.
Updated to 0.16.0:
Deprecation notice:
- SPHINCS+ was removed in 0.16.0.
Security issues:
- Fixed uninitialized
encaps_derandpointer dereference - CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification (bsc#1267007 bsc#1267001)
- Fixed Integer underflow in CROSS
crypto_sign_open() - Fixed incorrect array size when calling
secure_clean - Implemented optimization barrier
OQS_MEM_BLACK_BOXand applied toct_selectin FrodoKEM
Significant change:
FrodoKEM algorithm change:
- Existing FrodoKEM in 0.15.0 was renamed to ephemeral
FrodoKEM (
KEM_efrodokem_<640|976|1344>_<aes|shake>), and the salted variant of FrodoKEM was added under the prior names (KEM_frodokem_<640|976|1344>_<aes|shake>). Ephemeral FrodoKEM is recommended for applications where each keypair will encapsulate only a small number of shared secrets and ciphertexts. Standard (salted) FrodoKEM is recommended for applications where each keypair is expected to encapsulate large number of ciphertexts. Please consult upstream for more details. - mldsa-native integration:
mldsa-native is a secure, fast, and portable C90 implementation of the
ML-DSA post-quantum signature standard. It also includes optimized
builds for x86_64 and aarch64. It is now the default implementation
behind
SIG_ml_dsa_<44|65|87>. - Updated HQC implementation:
The HQC implementations in liboqs were updated to 20250822
spec. Its upstream switched from PQClean to the official
repo.
KEM_hqc_<1|3|5>is now enabled by default. - MQOM integration and memory-optimized build flag:
MQOM is a third-round candidate in NIST's Additional Digital
Signatures for the PQC Standardization Process. Portable,
x86_64-optimized, and memory-optimized implementations were
integrate into liboqs under
OQS_ENABLE_SIG_MQOM. - OpenSSH implementation of NTRU Prime:
A public-domain OpenSSH implementation of NTRUPrime761
replaced the PQClean implementation as the default backend for
KEM_ntruprime_sntrup761.
Bug fixes:
- Fixed incremental absorption bug in AVX512VL SHA3-512 #2442
- Implemented fallback for when
EVP_DigestSqueezeis unavailable #2433 - Added API for detecting stateful signature support at runtime #2434
- Fixed missing initialization and indexing bug in LMS #2416
- Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO #2403
- Limited pytest parallelism to prevent memory exhaustion in constrained environment #2397
- Fixed cuPQC ML-KEM derand symbol names and
#if/#elifchains #2396 - Tightened Windows compiler detection #2394
- Fixed mismatched macros in LMS #2379
- Made fuzzers tolerant to disabled algorithms #2359
- Removed inlined exponentiation in CROSS-RSDPG-1 #2357
- Fixed incorrect arg register update in AVX512 Keccak #2330
Update to 0.15.0:
-
Significant changes:
- Integrated SLH-DSA implementation from pq-code-package/slhdsa-c
- SLH-DSA ACVP tests (#2237)
- Integrate SLH-DSA-C Library (#2175)
- Added NTRU back (#2176)
- Removed all Dilithium implementations (#2275)
- Replaced SPHINCS+ with SLH-DSA for CMake build option OQS_ALGS_ENABLED=STD (#2290)
- Updated CROSS to version 2.2 (#2247)
- Included DeriveEncapsulation functionality (#2221)
- Integrated ML-KEM implementation from ICICLE-PQC (#2216)
-
Bug fixes:
- Fixed erroneously disabled LMS variants with build flag OQS_ENABLE_SIG_STFL_LMS (#2310)
- Fixed incorrect import in OV-III-pkc_skc (#2299)
- Fixed incorrect actual signature length in signature full-cycle speed test (#2293)
- Fixed ICICLE ML-KEM integration (#2288)
- Disabled strict aliasing on SPHINCS+-SHAKE (#2264)
- Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)
- Changed 64 bit add to 32 bit add to wrap on 32 bit counter for AES-CTR AES-NI implementation (#2252)
- Improved random number generator security (#2225)
- Added Classic McEliece sanitization patch (#2218)
-
Miscellaneous:
- Deprecated noregress scripts (#2295)
- Updated no-pass explanation for constant-time testing (#2294)
- Re-enabled all ACVP tests (#2283)
- Updated license info for ML-KEM (#2250)
- Added Poutine SASL (#2213)
- Updated ACVP to 1.1.0.40 (#2172)
- Switched to dev mode for 0.14.1 (#2199)
-
Deprecation notice: liboqs 0.15.0 is the last version to officially support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.
Updated to 0.14.0:
-
Key encapsulation mechanisms:
- HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.
- ML-KEM: Updated the default ML-KEM implementation to PQCP's mlkem-native v1.0.0.
-
Digital signature schemes:
- New API: added an API function to check if a signature scheme supports signing with a context string.
- SNOVA: added SNOVA from NIST Additional Signature Schemes Round 2.
-
Other changes:
- Added an AVX512VL-optimized backend for SHA3.
- Improved memory management throughout the codebase.
-
CVE-2025-52473: Disabled compiler optimizations for HQC to avoid secret-dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang from from the University of Melbourne and the Max Planck Institute for Security and Privacy for identifying the issue. (bsc#1246301)
-
new major library version liboqs.so.8
-
add -DOQS_ENABLE_KEM_HQC=ON even due to security issues, as otherwise we dropped binary compatibility with postquantumcryptoengine (bsc#1242701)
-
Do not embed the buildhost's kernel version to help reproducibility (bsc#1101107)
Updated to 0.13.0:
-
Key encapsulation mechanisms
- New API: Added a deterministic key generation and API for KEMs (only ML-KEM supported at the moment).
- ML-KEM: Changed the default ML-KEM implementation to PQCP's mlkem-native. There are three variants: Portable C, AVX2, and AArch64. Large +parts of these implementations are formally verified: all of the C code is verified for memory and type safety using CBMC and the functional correctness +of the core AArch64 assembly routines is verified using HOL-Light.
- ML-KEM: Added support for the ML-KEM implementation from Nvidia cuPQC, a GPU accelerated cryptography library.
- ML-KEM: Implementation from mlkem-native upstream updated to add Pair-wise Consistency Test (PCT) and Intel CET support.
- ML-KEM: Improved testing of ML-KEM keys.
- HQC: Disabled HQC by default until a new security flaw is fixed.
-
Digital signature schemes
- ML-DSA: Improved testing for ML-DSA.
- CROSS: Updated to NIST Additional Signatures Round 2 version.
- MAYO: Updated to NIST Additional Signatures Round 2 version.
- UOV: Added support for UOV algorithm from NIST Additional Signatures Round 2.
Update to 0.11.0:
- Hide all symbols except for OSSL_provider_init entrypoint
- corrects fixed test cert validity
- Update CROSS to version 2.2
- update contributing guide to point to more resilient script
- follow upstream and fixup Composites removal
- Add Brainpool hybrid KEM support
- Fix 'enable_tls' SIG algorithm mismatch
Updated to 0.10.0:
- Add SNOVA signatures
- Remove Composite Signature logic, templating, and documentation
- disable openssl.cnf which blocks some of our tests (bsc#1249081)
updated to 0.9.0:
- Adds support for UOV (NIST Additional Signatures Round 2)
- Adds support for Mayo (NIST Additional Signatures Round 2)
- Adds support for CROSS (NIST Additional Signatures Round 2)
- Disables HQC KEM by default, following liboqs v0.13.0, until a security flaw is fixed.
- Disables default support for Kyber (Round 3 version).
- Disables default support for Dilithium (Round 3 version).
- Restricts non-standard TLS group code points to IANA private use range.
- Updates TLS group code point and name for ML-KEM 1024 hybrid SecP384r1MLKEM1024.
- Disables ML-KEM (along with certain hybrid variants) and ML-DSA (along with all composite/hybrid variants) when oqs-provider is loaded with OpenSSL (version >= 3.5.0) which offers native support for some of these algorithms. Please see README.md for detailed information.
- fixes build with openssl 3.5 (bsc#1244617)
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:3420-1
- E-Mail link for SUSE-SU-2026:3420-1
- SUSE Security Ratings
- SUSE Bug 1101107
- SUSE Bug 1242701
- SUSE Bug 1244617
- SUSE Bug 1245315
- SUSE Bug 1246301
- SUSE Bug 1249081
- SUSE Bug 1267001
- SUSE Bug 1267007
- SUSE CVE CVE-2025-52473 page
- SUSE CVE CVE-2026-44518 page
- SUSE CVE CVE-2026-46344 page
Описание
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels above -O0 (-O1, -O2, etc). A proof-of-concept local attack exploits this secret-dependent information to recover the entire secret key. This vulnerability is fixed in 0.14.0.
Затронутые продукты
Ссылки
- CVE-2025-52473
- SUSE Bug 1246301
Описание
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not validate the caller-supplied length and proceeds to read past the end of the buffer. The out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.
Затронутые продукты
Ссылки
- CVE-2026-44518
- SUSE Bug 1267001
- SUSE Bug 1267007
Описание
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized signature buffer for the declared algorithm but a public key whose OID bytes (pk[0..3]) reference a different XMSS parameter set with a larger sig_bytes, the implementation re-parses the OID from the public key inside xmss_sign_open / xmssmt_sign_open and uses the resulting (larger) sig_bytes to index the caller-supplied signature buffer. As with CVE-2026-44518, the out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.
Затронутые продукты
Ссылки
- CVE-2026-46344
- SUSE Bug 1267007