freenode

← digests

HAWK break, OpenOffice RCE, FN-DSA plan, McEliece claim

Security & Cryptography2026-10-03

Post-quantum cryptography saw a practical key-recovery result against HAWK, a claimed quasipolynomial attack on Classic McEliece, and a NIST plan update for FN-DSA. Critical remote code execution and denial-of-service flaws were also disclosed in Apache OpenOffice and the Apache Directory LDAP API.

HAWK key recovery reduced to SVP in dimension n/2 + 1

Anthropic researchers announced a key-recovery attack on the HAWK signature scheme that reduces the underlying hard problem to SVP in dimension n/2 + 1. The result includes a practical break of HAWK-256. The lowered dimension materially changes the security estimate for a scheme that has been discussed in post-quantum standardization.

Critical RCE in Apache OpenOffice via malicious documents

CVE-2026-59265 was disclosed against Apache OpenOffice: opening a malicious document can lead to system takeover through the Java integration. A fix is pending in version 4.1.17. Users who process untrusted office files face immediate risk until they can apply the update.

NIST proposes fixed-point FN-DSA in FIPS 206

NIST presented a new plan for FN-DSA that targets a fixed-point specification in FIPS 206, complete with exact-match known-answer tests and component tests. The change follows recent implementation papers on Falcon. Developers building Falcon-derived code will need to align with the revised test and precision requirements.

Quasipolynomial attack claimed on Classic McEliece

A new eprint claims a quasipolynomial distinguisher together with a heuristic decryption attack on Classic McEliece. The ensuing pqc-forum thread also contained a disclosure dispute involving Apon. Because Classic McEliece remains a leading code-based candidate, the claimed complexity reduction requires careful independent scrutiny.

Multiple critical flaws in Apache Directory LDAP API

Four CVEs were published for the Apache Directory LDAP API. CVE-2026-103877 describes unsafe loading of Java code from LDAP schema elements that enables deserialization RCE in 2.1.0 through 2.1.8; CVE-2026-103878 covers injection of plaintext responses during StartTLS. Two denial-of-service issues affect the 1.2.x line before 1.2.9: excessive memory allocation in BER decode (CVE-2026-102731) and stack overflow from deeply nested search filters (CVE-2026-103552). Deployments that accept untrusted LDAP input should upgrade without delay.