Security and cryptography digest for 2026-10-06
Post-quantum cryptography threads led the day with a claimed quasipolynomial attack on Classic McEliece and a NIST plan for FN-DSA, while open source projects announced multiple library and tool fixes. Modeling assumptions in additional signature candidates and PGP parsing issues also drew comment.
Quasipolynomial attack claimed on Classic McEliece
A new eprint claims a quasipolynomial distinguisher and heuristic decryption for Classic McEliece. The pqc-forum thread ran to 103 messages from 15 participants and also contains a disclosure dispute involving Apon. Readers following NIST PQC candidates have reason to track whether the claim holds against this code-based scheme.
NIST sets fixed-point plan for FN-DSA
NIST proposes a fixed-point FN-DSA specification in FIPS 206 with exact-match KATs and component tests after recent Falcon implementation papers. The pqc-forum discussion involved 22 messages from 8 participants. The change aims to lock down the Falcon-derived signature path for standardization.
Ideal-cipher assumption flagged in SDitH and MQOM
An official Round 3 comment on additional signatures flags a non-conservative ideal-cipher assumption in SDitH and MQOM arising from known AES related-key distinguishers. The short pqc-forum exchange is technical. Designers and analysts of these schemes may need to revisit the underlying security reductions.
CUPS 2.4.20 lists multiple security fixes
CUPS announces an embargo policy change and lists multiple fixes with CVSS scores below 7 for the incoming 2.4.20 release via GHSA. The single oss-security notice covers the planned update. Operators of CUPS print services should prepare to apply the release.
gpg.fail authors issue retrospective and new PoC
The gpg.fail authors publish a retrospective talk with slides plus a new proof of concept. The oss-security thread of 20 messages from 11 participants then turns to PGP packet grammar flaws and tightening proposals. Developers working with OpenPGP parsing have fresh material on long-standing grammar weaknesses.
libexpat 2.9.0 fixes two parsing vulnerabilities
Libexpat 2.9.0 is released fixing two CVEs that cover an integer overflow and buffer validation issues in XML parsing. The oss-security announcement records the update. Software that embeds libexpat for XML handling should move to the new version.
FreeIPMI 1.6.20 repairs buffer overflows
FreeIPMI 1.6.20 is released with two buffer overflow fixes and the notice is forwarded to oss-security. The update addresses memory safety problems in the IPMI tooling. Administrators using FreeIPMI should install the corrected release.
Punk Perl module fails Origin check on Extended CONNECT
CVE-2026-104380 is published for Punk versions from 0.48 before 0.55 for Perl, which route HTTP/2 and later Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. The oss-security notice carries the details. Maintainers of services built on the Punk module need to upgrade past 0.55.