{"id":"SUSE-SU-2026:3420-1","summary":"Security update for liboqs, oqs-provider","details":"This update for liboqs, oqs-provider fixes the following issues:\n\n- disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite shows them not working.\n\nUpdated to 0.16.0:\n\n  Deprecation notice:\n\n  - SPHINCS+ was removed in 0.16.0.\n\n  Security issues:\n\n  - Fixed uninitialized `encaps_derand` pointer dereference\n  - CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification\n    (bsc#1267007 bsc#1267001)\n  - Fixed Integer underflow in CROSS `crypto_sign_open()`\n  - Fixed incorrect array size when calling `secure_clean`\n  - Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM\n\n  Significant change:\n\n  FrodoKEM algorithm change:\n\n  * Existing FrodoKEM in 0.15.0 was renamed to ephemeral\n    FrodoKEM (`KEM_efrodokem_\u003c640|976|1344\u003e_\u003caes|shake\u003e`), and\n    the salted variant of FrodoKEM was added under the prior names\n    (`KEM_frodokem_\u003c640|976|1344\u003e_\u003caes|shake\u003e`).\n    Ephemeral FrodoKEM is recommended for applications\n    where each keypair will encapsulate only a small number\n    of shared secrets and ciphertexts. Standard (salted)\n    FrodoKEM is recommended for applications where each keypair\n    is expected to encapsulate large number of ciphertexts. Please consult\n    [upstream](https://github.com/microsoft/PQCrypto-LWEKE/#frodokem-learning-with-errors-key-encapsulation)\n    for more details.\n  * mldsa-native integration:\n    mldsa-native is a secure, fast, and portable C90 implementation of the\n    ML-DSA post-quantum signature standard. It also includes optimized\n    builds for x86_64 and aarch64. It is now the default implementation\n    behind `SIG_ml_dsa_\u003c44|65|87\u003e`.\n  * Updated HQC implementation:\n    The HQC implementations in liboqs were updated to 20250822\n    spec. Its upstream switched from PQClean to the [official\n    repo](https://gitlab.com/pqc-hqc/hqc). `KEM_hqc_\u003c1|3|5\u003e` is now enabled\n    by default.\n  * MQOM integration and memory-optimized build flag:\n    MQOM is a third-round candidate in NIST's Additional Digital\n    Signatures for the PQC Standardization Process. Portable,\n    x86_64-optimized, and memory-optimized implementations were\n    integrate�into liboqs under `OQS_ENABLE_SIG_MQOM`.\n  * OpenSSH implementation of NTRU Prime:\n    A public-domain OpenSSH implementation of NTRUPrime761\n    replaced the PQClean implementation as the default backend for\n    `KEM_ntruprime_sntrup761`.\n\n  Bug fixes:\n\n  - Fixed incremental absorption bug in AVX512VL SHA3-512 [#2442](https://github.com/open-quantum-safe/liboqs/pull/2442)\n  - Implemented fallback for when `EVP_DigestSqueeze` is unavailable [#2433](https://github.com/open-quantum-safe/liboqs/pull/2433)\n  - Added API for detecting stateful signature support at runtime [#2434](https://github.com/open-quantum-safe/liboqs/pull/2434)\n  - Fixed missing initialization and indexing bug in LMS [#2416](https://github.com/open-quantum-safe/liboqs/pull/2416)\n  - Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO [#2403](https://github.com/open-quantum-safe/liboqs/pull/2403)\n  - Limited pytest parallelism to prevent memory exhaustion in constrained environment [#2397](https://github.com/open-quantum-safe/liboqs/pull/2397)\n  - Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains [#2396](https://github.com/open-quantum-safe/liboqs/pull/2396)\n  - Tightened Windows compiler detection [#2394](https://github.com/open-quantum-safe/liboqs/pull/2394)\n  - Fixed mismatched macros in LMS [#2379](https://github.com/open-quantum-safe/liboqs/pull/2379)\n  - Made fuzzers tolerant to disabled algorithms [#2359](https://github.com/open-quantum-safe/liboqs/pull/2359)\n  - Removed inlined exponentiation in CROSS-RSDPG-1 [#2357](https://github.com/open-quantum-safe/liboqs/pull/2357)\n  - Fixed incorrect arg register update in AVX512 Keccak [#2330](https://github.com/open-quantum-safe/liboqs/pull/2330)\n\nUpdate to 0.15.0:\n\n  * Significant changes:\n\n    - Integrated SLH-DSA implementation from pq-code-package/slhdsa-c\n    - SLH-DSA ACVP tests (#2237)\n    - Integrate SLH-DSA-C Library (#2175)\n    - Added NTRU back (#2176)\n    - Removed all Dilithium implementations (#2275)\n    - Replaced SPHINCS+ with SLH-DSA for CMake build option\n      OQS_ALGS_ENABLED=STD (#2290)\n    - Updated CROSS to version 2.2 (#2247)\n    - Included DeriveEncapsulation functionality (#2221)\n    - Integrated ML-KEM implementation from ICICLE-PQC (#2216)\n\n  * Bug fixes:\n\n    - Fixed erroneously disabled LMS variants with build flag\n      OQS_ENABLE_SIG_STFL_LMS (#2310)\n    - Fixed incorrect import in OV-III-pkc_skc (#2299)\n    - Fixed incorrect actual signature length in signature full-cycle\n      speed test (#2293)\n    - Fixed ICICLE ML-KEM integration (#2288)\n    - Disabled strict aliasing on SPHINCS+-SHAKE (#2264)\n    - Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)\n    - Changed 64 bit add to 32 bit add to wrap on 32 bit counter for\n      AES-CTR AES-NI implementation (#2252)\n    - Improved random number generator security (#2225)\n    - Added Classic McEliece sanitization patch (#2218)\n\n  * Miscellaneous:\n\n    - Deprecated noregress scripts (#2295)\n    - Updated no-pass explanation for constant-time testing (#2294)\n    - Re-enabled all ACVP tests (#2283)\n    - Updated license info for ML-KEM (#2250)\n    - Added Poutine SASL (#2213)\n    - Updated ACVP to 1.1.0.40 (#2172)\n    - Switched to dev mode for 0.14.1 (#2199)\n\n  * Deprecation notice: liboqs 0.15.0 is the last version to officially\n    support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and\n    replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.\n\nUpdated to 0.14.0:\n\n  * Key encapsulation mechanisms:\n\n    - HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.\n    - ML-KEM: Updated the default ML-KEM implementation to [PQCP's mlkem-native v1.0.0](https://github.com/pq-code-package/mlkem-native/releases/tag/v1.0.0).\n\n  * Digital signature schemes:\n\n    - New API: added an API function to check if a signature scheme supports signing with a context string.\n    - SNOVA: added [SNOVA](https://snova.pqclab.org/) from NIST Additional Signature Schemes Round 2.\n\n  * Other changes:\n\n     - Added an AVX512VL-optimized backend for SHA3.\n     - Improved memory management throughout the codebase.\n\n- CVE-2025-52473: Disabled compiler optimizations for HQC to avoid\n  secret-dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang\n  from from the University of Melbourne and the Max Planck Institute\n  for Security and Privacy for identifying the issue. (bsc#1246301)\n- new major library version liboqs.so.8\n\n- add -DOQS_ENABLE_KEM_HQC=ON even due to security issues, as otherwise\n  we dropped binary compatibility with postquantumcryptoengine (bsc#1242701)\n\n- Do not embed the buildhost's kernel version to help reproducibility (bsc#1101107)\n\nUpdated to 0.13.0:\n\n  - Key encapsulation mechanisms                                                                                                                                                             \n\n    - New API: Added a deterministic key generation and API for KEMs (only ML-KEM supported at the moment).\n    - ML-KEM: Changed the default ML-KEM implementation to [PQCP's mlkem-native](https://github.com/pq-code-package/mlkem-native). There are three variants: Portable C, AVX2, and AArch64. Large +parts of these implementations are formally verified: all of the C code is verified for memory and type safety using [CBMC](https://github.com/diffblue/cbmc) and the functional correctness +of the core AArch64 assembly routines is verified using [HOL-Light](https://github.com/jrh13/hol-light).\n    - ML-KEM: Added support for the ML-KEM implementation from [Nvidia cuPQC](https://developer.nvidia.com/cupqc), a GPU accelerated cryptography library.\n    - ML-KEM: Implementation from mlkem-native upstream updated to add Pair-wise Consistency Test (PCT) and Intel CET support.\n    - ML-KEM: Improved testing of ML-KEM keys.\n    - HQC: Disabled HQC by default until [a new security flaw](https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/Wiu4ZQo3fP8) is fixed.\n\n  - Digital signature schemes\n\n    - ML-DSA: Improved testing for ML-DSA.\n    - CROSS: Updated to NIST Additional Signatures Round 2 version.\n    - MAYO: Updated to NIST Additional Signatures Round 2 version.\n    - UOV: Added support for UOV algorithm from NIST Additional Signatures Round 2.\n\nUpdate to 0.11.0:\n\n  * Hide all symbols except for OSSL_provider_init entrypoint\n  * corrects fixed test cert validity\n  * Update CROSS to version 2.2\n  * update contributing guide to point to more resilient script\n  * follow upstream and fixup Composites removal\n  * Add Brainpool hybrid KEM support\n  * Fix 'enable_tls' SIG algorithm mismatch\n\nUpdated to 0.10.0:\n\n  * Add SNOVA signatures\n  * Remove Composite Signature logic, templating, and documentation\n\n- disable openssl.cnf which blocks some of our tests (bsc#1249081)\n\nupdated to 0.9.0:\n\n  - Adds support for UOV (NIST Additional Signatures Round 2)\n  - Adds support for Mayo (NIST Additional Signatures Round 2)\n  - Adds support for CROSS (NIST Additional Signatures Round 2)\n  - Disables HQC KEM by default, following liboqs v0.13.0, until a security flaw is fixed.\n  - Disables default support for Kyber (Round 3 version).\n  - Disables default support for Dilithium (Round 3 version).\n  - Restricts non-standard TLS group code points to IANA private use range.\n  - Updates TLS group code point and name for ML-KEM 1024 hybrid SecP384r1MLKEM1024.\n  - Disables ML-KEM (along with certain hybrid variants) and ML-DSA\n    (along with all composite/hybrid variants) when oqs-provider is loaded\n    with OpenSSL (version \u003e= 3.5.0) which offers native support for some\n    of these algorithms. Please see README.md for detailed information.\n- fixes build with openssl 3.5 (bsc#1244617)\n","modified":"2026-07-30T17:15:08.858956696Z","published":"2026-07-30T07:28:37Z","related":["CVE-2025-52473","CVE-2026-44518","CVE-2026-46344"],"upstream":["CVE-2025-52473","CVE-2026-44518","CVE-2026-46344"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263420-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1101107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1242701"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46344"}],"affected":[{"package":{"name":"liboqs","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/liboqs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.16.0-150600.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs9":"0.16.0-150600.3.6.1","oqs-provider":"0.11.0.32-150600.3.9.1","liboqs-devel":"0.16.0-150600.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}},{"package":{"name":"oqs-provider","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/oqs-provider&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.0.32-150600.3.9.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs-devel":"0.16.0-150600.3.6.1","liboqs9":"0.16.0-150600.3.6.1","oqs-provider":"0.11.0.32-150600.3.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}},{"package":{"name":"liboqs","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/liboqs&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.16.0-150600.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs9":"0.16.0-150600.3.6.1","oqs-provider":"0.11.0.32-150600.3.9.1","liboqs-devel":"0.16.0-150600.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}},{"package":{"name":"oqs-provider","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/oqs-provider&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.0.32-150600.3.9.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs9":"0.16.0-150600.3.6.1","oqs-provider":"0.11.0.32-150600.3.9.1","liboqs-devel":"0.16.0-150600.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}},{"package":{"name":"liboqs","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/liboqs&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.16.0-150600.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"oqs-provider":"0.11.0.32-150600.3.9.1","liboqs-devel":"0.16.0-150600.3.6.1","liboqs9":"0.16.0-150600.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}},{"package":{"name":"oqs-provider","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/oqs-provider&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.0.32-150600.3.9.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs9":"0.16.0-150600.3.6.1","oqs-provider":"0.11.0.32-150600.3.9.1","liboqs-devel":"0.16.0-150600.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3420-1.json"}}],"schema_version":"1.8.0"}