logo

Critical Vulnerabilities in liboqs and oqs-provider Affecting openSUSE Systems

ID: 9bd1d7ed-930b-573c-889d-31198df43711

STIX ID: report--9bd1d7ed-930b-573c-889d-31198df43711

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-07-30

Date Updated: 2026-08-05

...
...

On July 30, 2026 liboqs and oqs-provider released an important security update that patches multiple vulnerabilities — notably CVE-2026-46344 and CVE-2026-44518 (out-of-bounds reads during signature verification), an uninitialized pointer dereference, and an integer underflow in crypto_sign_open(). The update also removes SPHINCS+ in v0.16.0, renames the FrodoKEM variant to ephemeral FrodoKEM, and disables KEM_HQC and SIG_MQOM on s390x due to test failures. Users are advised to apply the patches immediately as the flaws could allow unauthorized access or system compromise if exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.