Path to this page:
Subject: CVS commit: pkgsrc/security/oqs-provider
From: Jan Schaumann
Date: 2025-01-06 21:58:01
Message id: 20250106205801.B2646FC1D@cvs.NetBSD.org
Log Message:
Update to 0.8.0
Deprecation notice
This is to notify users of Kyber and Dilithium (Round
3 version) to switch to the ML-KEM (FIPS 203 final
version) and ML-DSA (FIPS 204 final version),
respectively, as support for both will be removed with
the next release of oqsprovider.
Security considerations
CVE-2024-54137: The associated liboqs v0.12.0 release
fixed a bug in HQC decapsulation that leads to
incorrect shared secret value during decapsulation
when called with an invalid ciphertext. Thank you to
Célian Glénaz and Dahmun Goudarzi from Quarkslab for
identifying the issue.
What's New
In addition to improving testing, CI, and fixing
platform specific build issues this release of
oqs-provider:
Updates IANA code points for ML-KEM and changes
FrodoKEM code points.
Adds support for ML-DSA (FIPS 204 final version).
Adds support for context strings in OpenSSL versions
>= 3.2.
Updates the implementation of
draft-ietf-lamps-pq-composite-sigs from version 01 to
version 02.
Adds a SBOM template in the CycloneDX 1.6 format.
Adds support for DTLS 1.3 (pending support in
OpenSSL).
Files: