PT-2026-44930 · Liboqs · Liboqs

Zulfff

·

Published

2026-05-29

·

Updated

2026-06-04

·

CVE-2026-44518

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions liboqs versions prior to 0.16.0
Description An out-of-bounds read exists in the XMSS and XMSS^MT stateful signature verification code. This occurs when the verification function is called with a signature buffer shorter than the expected size for the specified parameter set, as the implementation fails to validate the caller-supplied length and reads past the buffer end. The out-of-bounds bytes are used only for internal hash computation and are not returned to the caller, preventing data leakage. The primary impact is a potential denial of service through a process crash if the read operation accesses an unmapped memory page.
Recommendations Update to version 0.16.0.

Fix

DoS

RCE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44518

Affected Products

Liboqs