CROSS Implementation Buffer Overflow Vulnerability in Post-Quantum Signature Algorithm
Vulnerability
A buffer overflow vulnerability has been identified in the CROSS implementation of the post-quantum signature algorithm. This issue arises from an integer underflow in the 'crypto_sign_open()' function, leading to the overflow. The vulnerability exists in versions prior to commit 'fc6b7e7'.
Impact
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or memory corruption.
Remediation
Users can update to the version that includes commit 'fc6b7e7' to address this vulnerability.
Added: May 8, 2026, 5:08 PM
Updated: May 8, 2026, 5:08 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
8.1remediation
0.0relevance
7.8threat
3.2urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
