diff --git a/CHANGES.md b/CHANGES.md index 19bcc0e..323cedf 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -1,3 +1,16 @@ +# Version 0.16.0.1 - September 23, 2026 + +- Security fix: the automatic liboqs installation no longer runs commands + through a shell, which allowed command injection via `PYOQS_VERSION` and + the install paths, + https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8 +- Added support for the ML-DSA external-mu variants when liboqs provides + them, https://github.com/open-quantum-safe/liboqs-python/pull/154 +- Added installation instructions for Windows and Raspberry Pi, + https://github.com/open-quantum-safe/liboqs-python/pull/135 +- Releases are now published to PyPI automatically, + https://github.com/open-quantum-safe/liboqs-python/pull/150 + # Version 0.16.0 - July 23, 2026 - Updated to liboqs 0.16.0 diff --git a/README.md b/README.md index 02795e7..fb007cc 100644 --- a/README.md +++ b/README.md @@ -105,7 +105,8 @@ This is convenient in case you want to avoid installing liboqs manually, as described in the subsection above. By default, liboqs-python installs the liboqs release that matches its own -version. Set the `PYOQS_VERSION` environment variable to override this: +version; a maintenance release such as liboqs-python 0.16.0.1 installs liboqs +0.16.0. Set the `PYOQS_VERSION` environment variable to override this: ```shell export PYOQS_VERSION=0.16.0 # install a specific liboqs release diff --git a/RELEASE.md b/RELEASE.md index 9d544cb..f3f4532 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -1,16 +1,29 @@ -# liboqs-python version 0.16.0 +# liboqs-python version 0.16.0.1 --- -# Added in version 0.16.0 +This is a maintenance release of liboqs-python 0.16.0 that fixes a security +issue. It is still built for liboqs 0.16.0. All users of liboqs-python +0.10.0 through 0.16.0 who rely on liboqs being installed automatically +should upgrade. -- Updated to liboqs 0.16.0. -- Added the `PYOQS_VERSION` environment variable to override the liboqs - release that is installed automatically at runtime. -- Fixed the Windows shared library lookup to search for both `oqs.dll` and - `liboqs.dll`. -- Fixed a `StatefulSignature` segfault when liboqs is built without stateful - signature key generation support. +# Security fix in version 0.16.0.1 + +- **Shell command injection in automatic liboqs installation** + ([GHSA-pw23-r5gj-42g8](https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8)). + When liboqs was not found at import time, liboqs-python built it by running + git and CMake through a shell, so shell metacharacters in `PYOQS_VERSION`, + `OQS_INSTALL_PATH`, `HOME`, or `TMPDIR` could execute arbitrary commands. + These commands now run without a shell, and `PYOQS_VERSION` is validated. + +# Other changes in version 0.16.0.1 + +- Fixed automatic installation of liboqs release candidates (e.g., + `0.16.0-rc1`) and install paths that contain spaces. +- Added support for the ML-DSA external-mu variants when liboqs provides them + (they are not in liboqs 0.16.0). +- Added installation instructions for Windows and Raspberry Pi. +- Releases are now published to PyPI automatically. ## About @@ -34,9 +47,9 @@ See in particular limitations on intended use. ## Release notes -This release of liboqs-python was released on July 23, 2026. Its release +This release of liboqs-python was released on September 23, 2026. Its release page on GitHub is -https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0. +https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0.1. --- diff --git a/pyproject.toml b/pyproject.toml index 48f102a..5177af0 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,7 +1,7 @@ [project] name = "liboqs-python" requires-python = ">=3.10" -version = "0.16.1-dev" +version = "0.16.0.1" description = "Python bindings for liboqs, providing post-quantum public key cryptography algorithms" authors = [ { name = "Open Quantum Safe project", email = "contact@openquantumsafe.org" },