Back

MEDIUM

liboqs: XMSS Buffer Overread Bug

Published May 29, 2026

Description

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not validate the caller-supplied length and proceeds to read past the end of the buffer. The out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.

Affected products

Remediation

Red Hat statement

This is a Moderate denial of service vulnerability in liboqs, a cryptographic library used in Red Hat products. A remote attacker can trigger an out-of-bounds read during XMSS or XMSS^MT signature verification by supplying a malformed, undersized signature. This can lead to a crash of the verifying process, resulting in a denial of service.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 29, 2026
Updated May 29, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Analyzed
Modified Jul 21, 2026
Red Hat
Severity Moderate
Public date May 29, 2026
ENISA EUVD
Assigner GitHub_M
Published May 29, 2026
Updated May 29, 2026
Exploited since n/a
EUVD-2026-33412