Security and cryptography digest for 2026-09-29
Post-quantum cryptography discussions led the day alongside multiple vulnerability disclosures in widely used open source components. Classic McEliece faced expert scrutiny over a claimed attack while Flatpak, Apache Karaf, PCRE2, Kubernetes, and KVM received fixes, and NIST revised its FN-DSA plan.
Claimed quasipolynomial attack on Classic McEliece
A claimed quasipolynomial attack on Classic McEliece parameters triggered extensive debate on the pqc-forum list, spanning 55 messages from 11 participants. Experts examined the attack costs and practical viability against current parameter sets. Developers tracking code-based post-quantum candidates need to follow the assessment of whether the scheme remains suitable for standardization.
Flatpak 1.18.4 security fixes
Flatpak 1.18.4 was released to address six CVEs, including cases where malicious applications could overwrite or delete privileged files. The fixes were announced on the oss-security list. Users of the application sandboxing framework should update to prevent local privilege abuse by untrusted packages.
Apache Karaf JMX authorization bypass
CVE-2026-92142 discloses an authorization bypass in Apache Karaf JMX MBean lifecycle operations. The flaw allows createMBean and unregisterMBean calls without the required role checks under RBAC. Karaf operators must apply the corresponding patch to block unauthorized management actions.
PCRE2 JIT out-of-bounds write
PCRE2 version 10.49 fixes a JIT buffer overflow identified as an out-of-bounds write. With an attacker-controlled regular expression and a custom JIT stack, the issue can lead to code execution. Projects relying on the PCRE2 JIT compiler should upgrade promptly.
Apache Karaf jdbc command privilege escalation
CVE-2026-91048 reports missing authorization on the jdbc:* shell command scope in Apache Karaf. A user with only the viewer role can reach remote code execution by supplying unvalidated JDBC URLs to jdbc:ds-create. Administrators running Karaf shells need to restrict or patch the affected command set.
kubectl cp path traversal on Windows
CVE-2026-19444 is a path traversal flaw in kubectl cp that affects Windows only and carries a medium CVSS score of 6.5. It permits arbitrary file writes when copying from a container. Windows users of the Kubernetes command-line tool should obtain the fixed release.
KVM x86 host panic via SMM shadow MMU
A report on oss-security describes a Linux KVM/x86 shadow MMU bug, tested on kernel 6.1.74, that lets an L1 guest trigger a host panic through SMM and nested EPT. Hosts that enable nested virtualization with SMM support are exposed to denial of service from a guest. Operators should monitor for upstream mitigation.
Updated NIST plan for FN-DSA
NIST published a revised plan for FN-DSA under FIPS 206 on the pqc-forum list. The update mandates fixed-point arithmetic and a single signing procedure to support known-answer test validation. Implementers preparing for the forthcoming standard must align their code and test harnesses with these requirements.