freenode

← digests

McEliece attacks, Exim and kernel roots

Security & Cryptography2026-09-19

Post-quantum cryptography and core infrastructure both saw notable security movement. Classic McEliece parameters drew expert warnings after new attack papers, while Exim, Suricata, the Linux kernel, and related libraries shipped fixes for high-impact flaws.

Quasipolynomial attacks on Classic McEliece

New eprint papers describe quasipolynomial attacks against Classic McEliece. Discussion on the NIST pqc-forum led experts to recommend against the scheme's proposed parameters. The development matters for post-quantum standardization, where Classic McEliece has long been a leading code-based candidate.

Exim 4.100.1 security release

Exim 4.100.1 fixes four vulnerabilities, including a high-severity heap corruption flaw in proxy protocol handling. The issues affect versions 4.83 through 4.100. Operators of the widely deployed mail transfer agent have clear reason to upgrade.

gpg.fail authors and GnuPG maintainers exchange

GnuPG maintainers and the authors of gpg.fail debated a claimed remote code execution zero-day in gpgsm debug code together with a previously fixed libgcrypt RSASSA-PSS issue. The oss-security thread clarifies the practical status of these reports for users of the OpenPGP toolchain.

Suricata 8.0.7 fixes 67 vulnerabilities

Suricata 8.0.7 is a security release that resolves 67 vulnerabilities, the largest single count to date and partly driven by AI-assisted reports. Teams running the network IDS and IPS engine should treat the update as a priority.

Four Linux local root vulnerabilities

Four Linux kernel local-root flaws (DirtyAH6, PPPoEject, TUNderflow, and DiagSpill) were disclosed after embargo, complete with fixes and exploitation details. Follow-on discussion examined reducing attack surface by disabling unused modules.

libheif and libde265 advisories

Alan Coopersmith highlighted recent libheif and libde265 security advisories and recommended sandboxing untrusted decoders. Media-parsing libraries continue to present a frequent entry point for untrusted content.

Apache Neethi remote policy fetch hang

CVE-2026-91867 covers a moderate denial-of-service condition in Apache Neethi: remote policy fetch lacks a total timeout, so a slow server can hang the request indefinitely. The issue is fixed in 3.2.4.

Apache Neethi policy intersection DoS

CVE-2026-91866 addresses crafted policies that trigger unbounded work during WS-Policy intersection, producing denial of service. Apache Neethi 3.2.4 contains the fix for this moderate-severity flaw.