CROSS Implementation Buffer Overflow Vulnerability in Post-Quantum Signature Algorithm

Vulnerability

A buffer overflow vulnerability has been identified in the CROSS implementation of the post-quantum signature algorithm. This issue arises from an integer underflow in the 'crypto_sign_open()' function, leading to the overflow. The vulnerability exists in versions prior to commit 'fc6b7e7'.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or memory corruption.

Remediation

Users can update to the version that includes commit 'fc6b7e7' to address this vulnerability.

Added: May 8, 2026, 5:08 PM
Updated: May 8, 2026, 5:08 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
0.0
relevance
7.8
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.