freenode

← digests

X.Org and Foreman fixes, McEliece claims, OpenSSH 10.6

Security & Cryptography2026-10-07

Critical fixes landed for X.Org and Foreman while post-quantum threads covered a new isogeny NIKE, Classic McEliece attack claims, and an FN-DSA plan. OpenSSH 10.6 also shipped, alongside Impala and PGP follow-ups.

X.Org fixes multiple X server and Xwayland flaws

X.Org published a security advisory for several issues in xorg-server and Xwayland. Among them is a double-free in XKB that can lead to code execution. Operators of X11 and Xwayland stacks should apply the updates.

Foreman Safemode bypass yields critical RCE

CVE-2026-96658 covers a Safemode bypass in Foreman that enables remote code execution. The flaw is rated CVSS 9.9 and is fixed in 3.19.2 and 5.0.1. Foreman administrators need to upgrade those releases.

MIKE: isogeny-based post-quantum NIKE released

Researchers announced the first release of MIKE (Module Isogeny Key Exchange), a post-quantum non-interactive key exchange built on isogenies. The design aims for small keys and ships constant-time code in C and Rust. Protocol designers evaluating PQ NIKEs gain another compact option to study.

Quasipolynomial attack claims against Classic McEliece

A new eprint asserts a quasipolynomial distinguisher and heuristic decryption for Classic McEliece. The pqc-forum thread ran long and heated, and also included a disclosure dispute involving Apon. Because Classic McEliece remains in the NIST PQC set, the claims call for independent verification.

NIST proposes fixed-point FN-DSA for FIPS 206

NIST outlined a fixed-point FN-DSA specification destined for FIPS 206, with exact-match KATs and component tests. The plan follows recent Falcon implementation papers. Implementers of lattice signatures should track the revised test and spec approach.

OpenSSH 10.6 released

OpenSSH 10.6 is out. The team observed a rise in AI-reported bugs and said it will ship fixes more often. Distributors and SSH operators should schedule the update.

Apache Impala path traversal for untrusted JARs

CVE-2026-90466 reports path traversal in Apache Impala 4.5.2 that can execute JARs outside trusted_jar_paths. The disclosure was a single oss-security post. Impala deployments should tighten trusted paths and apply fixes.

gpg.fail authors post retrospective and new PoC

The gpg.fail authors published a retrospective talk and slides plus a new proof of concept. Thread discussion moved to PGP packet grammar weaknesses and proposals to tighten the format. PGP implementers can use the analysis when hardening parsers.