{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2025-48946","title":"Title"},{"category":"description","text":"liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malformed ciphertexts sharing the same implicit rejection value. Currently, no concrete attack on the algorithm is known. However, prospective users of HQC must take extra care when using the algorithm in protocols involving key derivation. In particular, HQC does not provide the same security guarantees as Kyber or ML-KEM. There is currently no patch for the HQC flaw available in liboqs, so HQC is disabled by default in liboqs starting from version 0.13.0. OQS will update its implementation after the HQC team releases an updated algorithm specification.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2025-48946","url":"https://www.suse.com/security/cve/CVE-2025-48946"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1243903 for CVE-2025-48946","url":"https://bugzilla.suse.com/1243903"}],"title":"SUSE CVE CVE-2025-48946","tracking":{"current_release_date":"2026-03-13T14:07:49Z","generator":{"date":"2025-06-03T02:39:13Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2025-48946","initial_release_date":"2025-06-03T02:39:13Z","revision_history":[{"date":"2025-06-03T02:39:13Z","number":"2","summary":"Current version"},{"date":"2025-07-04T14:37:15Z","number":"3","summary":"Current version"},{"date":"2025-08-06T23:22:20Z","number":"4","summary":"Current version"},{"date":"2025-08-26T23:23:01Z","number":"5","summary":"Current version"},{"date":"2025-12-25T00:29:09Z","number":"6","summary":"more updates marked as affected"},{"date":"2026-02-03T00:28:45Z","number":"7","summary":"more updates marked as affected"},{"date":"2026-03-11T16:55:32Z","number":"8","summary":"unknown changes"},{"date":"2026-03-13T14:07:49Z","number":"9","summary":"more updates marked as affected"}],"status":"interim","version":"9"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Linux Enterprise Desktop 15 SP6","product":{"name":"SUSE Linux Enterprise Desktop 15 SP6","product_id":"SUSE Linux Enterprise Desktop 15 SP6","product_identification_helper":{"cpe":"cpe:/o:suse:sled:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise Desktop 15 SP7","product":{"name":"SUSE Linux Enterprise Desktop 15 SP7","product_id":"SUSE Linux Enterprise Desktop 15 SP7","product_identification_helper":{"cpe":"cpe:/o:suse:sled:15:sp7"}}},{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15 SP6","product":{"name":"SUSE Linux Enterprise High Performance Computing 15 SP6","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP6","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15 SP7","product":{"name":"SUSE Linux Enterprise High Performance Computing 15 SP7","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP7","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc:15:sp7"}}},{"category":"product_name","name":"SUSE Linux Enterprise Module for Basesystem 15 SP6","product":{"name":"SUSE Linux Enterprise Module for Basesystem 15 SP6","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP6","product_identification_helper":{"cpe":"cpe:/o:suse:sle-module-basesystem:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise Module for Basesystem 15 SP7","product":{"name":"SUSE Linux Enterprise Module for Basesystem 15 SP7","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP7","product_identification_helper":{"cpe":"cpe:/o:suse:sle-module-basesystem:15:sp7"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15 SP6","product":{"name":"SUSE Linux Enterprise Server 15 SP6","product_id":"SUSE Linux Enterprise Server 15 SP6","product_identification_helper":{"cpe":"cpe:/o:suse:sles:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15 SP6-LTSS","product":{"name":"SUSE Linux Enterprise Server 15 SP6-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP6-LTSS","product_identification_helper":{"cpe":"cpe:/o:suse:sles-ltss:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15 SP7","product":{"name":"SUSE Linux Enterprise Server 15 SP7","product_id":"SUSE Linux Enterprise Server 15 SP7","product_identification_helper":{"cpe":"cpe:/o:suse:sles:15:sp7"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 16.0","product":{"name":"SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0","product_identification_helper":{"cpe":"cpe:/o:suse:sles:16:16.0:server"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP Applications 15 SP6","product":{"name":"SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_identification_helper":{"cpe":"cpe:/o:suse:sles_sap:15:sp6"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP Applications 15 SP7","product":{"name":"SUSE Linux Enterprise Server for SAP Applications 15 SP7","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP7","product_identification_helper":{"cpe":"cpe:/o:suse:sles_sap:15:sp7"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP applications 16.0","product":{"name":"SUSE Linux Enterprise Server for SAP applications 16.0","product_id":"SUSE Linux Enterprise Server for SAP applications 16.0","product_identification_helper":{"cpe":"cpe:/o:suse:sles:16:16.0:server-sap"}}},{"category":"product_name","name":"openSUSE Leap 15.6","product":{"name":"openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.6"}}},{"category":"product_version","name":"liboqs","product":{"name":"liboqs","product_id":"liboqs","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs@"}}},{"category":"product_version","name":"liboqs-devel","product":{"name":"liboqs-devel","product_id":"liboqs-devel","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs-devel@?upstream=liboqs.src.rpm"}}},{"category":"product_version","name":"liboqs-devel-32bit","product":{"name":"liboqs-devel-32bit","product_id":"liboqs-devel-32bit","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs-devel-32bit@?upstream=liboqs.src.rpm"}}},{"category":"product_version","name":"liboqs4","product":{"name":"liboqs4","product_id":"liboqs4","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs4@?upstream=liboqs.src.rpm"}}},{"category":"product_version","name":"liboqs4-32bit","product":{"name":"liboqs4-32bit","product_id":"liboqs4-32bit","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs4-32bit@?upstream=liboqs.src.rpm"}}},{"category":"product_version","name":"liboqs7","product":{"name":"liboqs7","product_id":"liboqs7","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs7@?upstream=liboqs.src.rpm"}}},{"category":"product_version","name":"liboqs7-32bit","product":{"name":"liboqs7-32bit","product_id":"liboqs7-32bit","product_identification_helper":{"cpe":"cpe:2.3:a:openquantumsafe:liboqs:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/liboqs7-32bit@?upstream=liboqs.src.rpm"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server 15 SP6","product_id":"SUSE Linux Enterprise Server 15 SP6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise Server 15 SP6","product_id":"SUSE Linux Enterprise Server 15 SP6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server 15 SP6","product_id":"SUSE Linux Enterprise Server 15 SP6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server 15 SP6","product_id":"SUSE Linux Enterprise Server 15 SP6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Desktop 15 SP6","product_id":"SUSE Linux Enterprise Desktop 15 SP6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise Desktop 15 SP6","product_id":"SUSE Linux Enterprise Desktop 15 SP6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Desktop 15 SP6","product_id":"SUSE Linux Enterprise Desktop 15 SP6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Desktop 15 SP6","product_id":"SUSE Linux Enterprise Desktop 15 SP6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server for SAP Applications 15 SP6","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise High Performance Computing 15 SP6","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise High Performance Computing 15 SP6","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise High Performance Computing 15 SP6","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise High Performance Computing 15 SP6","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Module for Basesystem 15 SP6","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise Module for Basesystem 15 SP6","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Module for Basesystem 15 SP6","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Module for Basesystem 15 SP6","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server 15 SP7","product_id":"SUSE Linux Enterprise Server 15 SP7:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server 15 SP7","product_id":"SUSE Linux Enterprise Server 15 SP7:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server 15 SP7","product_id":"SUSE Linux Enterprise Server 15 SP7:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Desktop 15 SP7","product_id":"SUSE Linux Enterprise Desktop 15 SP7:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Desktop 15 SP7","product_id":"SUSE Linux Enterprise Desktop 15 SP7:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Desktop 15 SP7","product_id":"SUSE Linux Enterprise Desktop 15 SP7:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Desktop 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server for SAP Applications 15 SP7","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server for SAP Applications 15 SP7","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server for SAP Applications 15 SP7","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise High Performance Computing 15 SP7","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise High Performance Computing 15 SP7","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise High Performance Computing 15 SP7","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Module for Basesystem 15 SP7","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Module for Basesystem 15 SP7","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Module for Basesystem 15 SP7","product_id":"SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Module for Basesystem 15 SP7"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server 15 SP6-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6-LTSS"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of SUSE Linux Enterprise Server 15 SP6-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6-LTSS"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server 15 SP6-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6-LTSS"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server 15 SP6-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP6-LTSS"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of SUSE Linux Enterprise Server for SAP applications 16.0","product_id":"SUSE Linux Enterprise Server for SAP applications 16.0:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP applications 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of SUSE Linux Enterprise Server for SAP applications 16.0","product_id":"SUSE Linux Enterprise Server for SAP applications 16.0:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP applications 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of SUSE Linux Enterprise Server for SAP applications 16.0","product_id":"SUSE Linux Enterprise Server for SAP applications 16.0:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP applications 16.0"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs-devel"},"product_reference":"liboqs-devel","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs-devel-32bit as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs-devel-32bit"},"product_reference":"liboqs-devel-32bit","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4 as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs4"},"product_reference":"liboqs4","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs4-32bit as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs4-32bit"},"product_reference":"liboqs4-32bit","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7 as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs7"},"product_reference":"liboqs7","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs7-32bit as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs7-32bit"},"product_reference":"liboqs7-32bit","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"liboqs as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:liboqs"},"product_reference":"liboqs","relates_to_product_reference":"openSUSE Leap 15.6"}]},"vulnerabilities":[{"cve":"CVE-2025-48946","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2025-48946"}],"notes":[{"category":"general","text":"liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malformed ciphertexts sharing the same implicit rejection value. Currently, no concrete attack on the algorithm is known. However, prospective users of HQC must take extra care when using the algorithm in protocols involving key derivation. In particular, HQC does not provide the same security guarantees as Kyber or ML-KEM. There is currently no patch for the HQC flaw available in liboqs, so HQC is disabled by default in liboqs starting from version 0.13.0. OQS will update its implementation after the HQC team releases an updated algorithm specification.","title":"CVE description"}],"product_status":{"known_affected":["SUSE Linux Enterprise Desktop 15 SP6:liboqs","SUSE Linux Enterprise Desktop 15 SP6:liboqs-devel","SUSE Linux Enterprise Desktop 15 SP6:liboqs4","SUSE Linux Enterprise Desktop 15 SP6:liboqs7","SUSE Linux Enterprise Desktop 15 SP7:liboqs","SUSE Linux Enterprise Desktop 15 SP7:liboqs-devel","SUSE Linux Enterprise Desktop 15 SP7:liboqs7","SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs","SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs-devel","SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs4","SUSE Linux Enterprise High Performance Computing 15 SP6:liboqs7","SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs","SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs-devel","SUSE Linux Enterprise High Performance Computing 15 SP7:liboqs7","SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs","SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs-devel","SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs4","SUSE Linux Enterprise Module for Basesystem 15 SP6:liboqs7","SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs","SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs-devel","SUSE Linux Enterprise Module for Basesystem 15 SP7:liboqs7","SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs","SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs-devel","SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs4","SUSE Linux Enterprise Server 15 SP6-LTSS:liboqs7","SUSE Linux Enterprise Server 15 SP6:liboqs","SUSE Linux Enterprise Server 15 SP6:liboqs-devel","SUSE Linux Enterprise Server 15 SP6:liboqs4","SUSE Linux Enterprise Server 15 SP6:liboqs7","SUSE Linux Enterprise Server 15 SP7:liboqs","SUSE Linux Enterprise Server 15 SP7:liboqs-devel","SUSE Linux Enterprise Server 15 SP7:liboqs7","SUSE Linux Enterprise Server 16.0:liboqs","SUSE Linux Enterprise Server 16.0:liboqs-devel","SUSE Linux Enterprise Server 16.0:liboqs7","SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs","SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs-devel","SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs4","SUSE Linux Enterprise Server for SAP Applications 15 SP6:liboqs7","SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs","SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs-devel","SUSE Linux Enterprise Server for SAP Applications 15 SP7:liboqs7","SUSE Linux Enterprise Server for SAP applications 16.0:liboqs","SUSE Linux Enterprise Server for SAP applications 16.0:liboqs-devel","SUSE Linux Enterprise Server for SAP applications 16.0:liboqs7","openSUSE Leap 15.6:liboqs","openSUSE Leap 15.6:liboqs-devel","openSUSE Leap 15.6:liboqs-devel-32bit","openSUSE Leap 15.6:liboqs4","openSUSE Leap 15.6:liboqs4-32bit","openSUSE Leap 15.6:liboqs7","openSUSE Leap 15.6:liboqs7-32bit"]},"references":[{"category":"external","summary":"CVE-2025-48946","url":"https://www.suse.com/security/cve/CVE-2025-48946"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1243903 for CVE-2025-48946","url":"https://bugzilla.suse.com/1243903"}],"threats":[{"category":"impact","date":"2025-05-30T22:01:17Z","details":"moderate"}],"title":"CVE-2025-48946"}]}