liboqs: XMSS Buffer Overread Bug
Published May 29, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.30%
Description
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffer shorter than the expected signature size for the given parameter set, the implementation does not validate the caller-supplied length and proceeds to read past the end of the buffer. The out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.
Affected products
-
- Version < 0.16.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open-Quantum-Safe | Liboqs | n/a |
|
- ≤ 0.15.0
No data.
Red Hat Enterprise Linux 10
liboqs
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | liboqs | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is a Moderate denial of service vulnerability in liboqs, a cryptographic library used in Red Hat products. A remote attacker can trigger an out-of-bounds read during XMSS or XMSS^MT signature verification by supplying a malformed, undersized signature. This can lead to a crash of the verifying process, resulting in a denial of service.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-44518 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2483392 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33412 Advisory
- https://github.com/open-quantum-safe/liboqs/commit/ef70dea7c85e5637f37828d75e5b9bb29dbfe513 x_refsource_MISCPatch
- https://github.com/open-quantum-safe/liboqs/security/advisories/GHSA-wf7v-fhxj-73m2 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44518
- https://www.cve.org/CVERecord?id=CVE-2026-44518
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-44518 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2483392 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33412 | Advisory | |
| https://github.com/open-quantum-safe/liboqs/commit/ef70dea7c85e5637f37828d75e5b9bb29dbfe513 | x_refsource_MISCPatch | |
| https://github.com/open-quantum-safe/liboqs/security/advisories/GHSA-wf7v-fhxj-73m2 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-44518 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-44518 |
Change history (0)
No recorded changes yet.