{"id":"openSUSE-SU-2026:21634-1","summary":"Security update for liboqs","details":"This update for liboqs fixes the following issues:\n\nChanges in liboqs:\n\nUpdated to 0.16.0:\n\n  Deprecation notice:\n\n  - SPHINCS+ was removed in 0.16.0.\n\n  Security issues:\n\n  - Fixed uninitialized `encaps_derand` pointer dereference\n  - CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT signature verification\n    (bsc#1267007 bsc#1267001)\n  - Fixed Integer underflow in CROSS `crypto_sign_open()`\n  - Fixed incorrect array size when calling `secure_clean`\n  - Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to `ct_select` in FrodoKEM\n\n  Significant change:\n\n  FrodoKEM algorithm change:\n\n  * Existing FrodoKEM in 0.15.0 was renamed to ephemeral\n    FrodoKEM (`KEM_efrodokem_\u003c640|976|1344\u003e_\u003caes|shake\u003e`), and\n    the salted variant of FrodoKEM was added under the prior names\n    (`KEM_frodokem_\u003c640|976|1344\u003e_\u003caes|shake\u003e`).\n\n    Ephemeral FrodoKEM is recommended for applications\n    where each keypair will encapsulate only a small number\n    of shared secrets and ciphertexts. Standard (salted)\n    FrodoKEM is recommended for applications where each keypair\n    is expected to encapsulate large number of ciphertexts. Please consult\n    [upstream](https://github.com/microsoft/PQCrypto-LWEKE/#frodokem-learning-with-errors-key-encapsulation)\n    for more details.\n\n  * mldsa-native integration:\n\n    mldsa-native is a secure, fast, and portable C90 implementation of the\n    ML-DSA post-quantum signature standard. It also includes optimized\n    builds for x86_64 and aarch64. It is now the default implementation\n    behind `SIG_ml_dsa_\u003c44|65|87\u003e`.\n\n  * Updated HQC implementation:\n\n    The HQC implementations in liboqs were updated to 20250822\n    spec. Its upstream switched from PQClean to the [official\n    repo](https://gitlab.com/pqc-hqc/hqc). `KEM_hqc_\u003c1|3|5\u003e` is now enabled\n    by default.\n\n  * MQOM integration and memory-optimized build flag:\n\n    MQOM is a third-round candidate in NIST's Additional Digital\n    Signatures for the PQC Standardization Process. Portable,\n    x86_64-optimized, and memory-optimized implementations were\n    integrate�into liboqs under `OQS_ENABLE_SIG_MQOM`.\n\n\n  * OpenSSH implementation of NTRU Prime:\n\n    A public-domain OpenSSH implementation of NTRUPrime761\n    replaced the PQClean implementation as the default backend for\n    `KEM_ntruprime_sntrup761`.\n\n  Bug fixes:\n\n  - Fixed incremental absorption bug in AVX512VL SHA3-512 [#2442](https://github.com/open-quantum-safe/liboqs/pull/2442)\n  - Implemented fallback for when `EVP_DigestSqueeze` is unavailable [#2433](https://github.com/open-quantum-safe/liboqs/pull/2433)\n  - Added API for detecting stateful signature support at runtime [#2434](https://github.com/open-quantum-safe/liboqs/pull/2434)\n  - Fixed missing initialization and indexing bug in LMS [#2416](https://github.com/open-quantum-safe/liboqs/pull/2416)\n  - Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO [#2403](https://github.com/open-quantum-safe/liboqs/pull/2403)\n  - Limited pytest parallelism to prevent memory exhaustion in constrained environment [#2397](https://github.com/open-quantum-safe/liboqs/pull/2397)\n  - Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains [#2396](https://github.com/open-quantum-safe/liboqs/pull/2396)\n  - Tightened Windows compiler detection [#2394](https://github.com/open-quantum-safe/liboqs/pull/2394)\n  - Fixed mismatched macros in LMS [#2379](https://github.com/open-quantum-safe/liboqs/pull/2379)\n  - Made fuzzers tolerant to disabled algorithms [#2359](https://github.com/open-quantum-safe/liboqs/pull/2359)\n  - Removed inlined exponentiation in CROSS-RSDPG-1 [#2357](https://github.com/open-quantum-safe/liboqs/pull/2357)\n  - Fixed incorrect arg register update in AVX512 Keccak [#2330](https://github.com/open-quantum-safe/liboqs/pull/2330)\n\n- Update to 0.15.0:\n  * Significant changes:\n    - Integrated SLH-DSA implementation from pq-code-package/slhdsa-c\n    - SLH-DSA ACVP tests (#2237)\n    - Integrate SLH-DSA-C Library (#2175)\n    - Added NTRU back (#2176)\n    - Removed all Dilithium implementations (#2275)\n    - Replaced SPHINCS+ with SLH-DSA for CMake build option\n      OQS_ALGS_ENABLED=STD (#2290)\n    - Updated CROSS to version 2.2 (#2247)\n    - Included DeriveEncapsulation functionality (#2221)\n    - Integrated ML-KEM implementation from ICICLE-PQC (#2216)\n  * Bug fixes:\n    - Fixed erroneously disabled LMS variants with build flag\n      OQS_ENABLE_SIG_STFL_LMS (#2310)\n    - Fixed incorrect import in OV-III-pkc_skc (#2299)\n    - Fixed incorrect actual signature length in signature full-cycle\n      speed test (#2293)\n    - Fixed ICICLE ML-KEM integration (#2288)\n    - Disabled strict aliasing on SPHINCS+-SHAKE (#2264)\n    - Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)\n    - Changed 64 bit add to 32 bit add to wrap on 32 bit counter for\n      AES-CTR AES-NI implementation (#2252)\n    - Improved random number generator security (#2225)\n    - Added Classic McEliece sanitization patch (#2218)\n  * Miscellaneous:\n    - Deprecated noregress scripts (#2295)\n    - Updated no-pass explanation for constant-time testing (#2294)\n    - Re-enabled all ACVP tests (#2283)\n    - Updated license info for ML-KEM (#2250)\n    - Added Poutine SASL (#2213)\n    - Updated ACVP to 1.1.0.40 (#2172)\n    - Switched to dev mode for 0.14.1 (#2199)\n  * Deprecation notice: liboqs 0.15.0 is the last version to officially\n    support SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and\n    replaced by SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.\n\nUpdated to 0.14.0:\n\n  * Key encapsulation mechanisms:\n    - HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.\n    - ML-KEM: Updated the default ML-KEM implementation to [PQCP's mlkem-native v1.0.0](https://github.com/pq-code-package/mlkem-native/releases/tag/v1.0.0).\n  * Digital signature schemes:\n    - New API: added an API function to check if a signature scheme supports signing with a context string.\n    - SNOVA: added [SNOVA](https://snova.pqclab.org/) from NIST Additional Signature Schemes Round 2.\n\n  * Other changes:\n     - Added an AVX512VL-optimized backend for SHA3.\n     - Improved memory management throughout the codebase.\n\n- CVE-2025-52473: Disabled compiler optimizations for HQC to avoid\n  secret-dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang\n  from from the University of Melbourne and the Max Planck Institute\n  for Security and Privacy for identifying the issue. (bsc#1246301)\n","modified":"2026-08-27T18:23:37.161204702Z","published":"2026-08-24T19:07:16Z","related":["CVE-2025-52473","CVE-2026-44518","CVE-2026-46344"],"upstream":["CVE-2025-52473","CVE-2026-44518","CVE-2026-46344"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46344"}],"affected":[{"package":{"name":"liboqs","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/liboqs&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.16.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"oqs-provider":"0.11.0.32-160000.1.1","liboqs-devel":"0.16.0-160000.1.1","liboqs9":"0.16.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21634-1.json"}},{"package":{"name":"oqs-provider","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/oqs-provider&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.0.32-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"liboqs-devel":"0.16.0-160000.1.1","liboqs9":"0.16.0-160000.1.1","oqs-provider":"0.11.0.32-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21634-1.json"}}],"schema_version":"1.9.0"}