CVE-2026-41509

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cross-crypto:cross-implementation:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-08 14:16

Updated : 2026-06-17 10:46


NVD link : CVE-2026-41509

Mitre link : CVE-2026-41509

CVE.ORG link : CVE-2026-41509


JSON object : View

Products Affected

cross-crypto

  • cross-implementation
CWE
CWE-121

Stack-based Buffer Overflow

CWE-122

Heap-based Buffer Overflow