From 50992f0e39fd456b8d1e887f011559854a8fcd89 Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Wed, 23 Sep 2026 11:11:35 -0400 Subject: [PATCH 1/2] Prepare 0.16.0.1 release Maintenance release of liboqs-python 0.16.0 carrying the fix for GHSA-pw23-r5gj-42g8 (shell command injection in automatic liboqs installation). It still pairs with liboqs 0.16.0. - Bump version 0.16.1-dev -> 0.16.0.1 (pyproject.toml); the runtime auto-installer maps this to the liboqs 0.16.0 tag. - CHANGES.md: add the 0.16.0.1 section (release date left as TODO). - RELEASE.md: rewrite for 0.16.0.1, leading with the security fix (release date left as TODO). - README.md: note that a four-part maintenance version installs the matching three-part liboqs release. Co-Authored-By: Claude Opus 5.5 Signed-off-by: Douglas Stebila --- CHANGES.md | 13 +++++++++++++ README.md | 3 ++- RELEASE.md | 35 ++++++++++++++++++++++++----------- pyproject.toml | 2 +- 4 files changed, 40 insertions(+), 13 deletions(-) diff --git a/CHANGES.md b/CHANGES.md index 19bcc0e..fbe2029 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -1,3 +1,16 @@ +# Version 0.16.0.1 - TODO + +- Security fix: the automatic liboqs installation no longer runs commands + through a shell, which allowed command injection via `PYOQS_VERSION` and + the install paths, + https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8 +- Added support for the ML-DSA external-mu variants when liboqs provides + them, https://github.com/open-quantum-safe/liboqs-python/pull/154 +- Added installation instructions for Windows and Raspberry Pi, + https://github.com/open-quantum-safe/liboqs-python/pull/135 +- Releases are now published to PyPI automatically, + https://github.com/open-quantum-safe/liboqs-python/pull/150 + # Version 0.16.0 - July 23, 2026 - Updated to liboqs 0.16.0 diff --git a/README.md b/README.md index 02795e7..fb007cc 100644 --- a/README.md +++ b/README.md @@ -105,7 +105,8 @@ This is convenient in case you want to avoid installing liboqs manually, as described in the subsection above. By default, liboqs-python installs the liboqs release that matches its own -version. Set the `PYOQS_VERSION` environment variable to override this: +version; a maintenance release such as liboqs-python 0.16.0.1 installs liboqs +0.16.0. Set the `PYOQS_VERSION` environment variable to override this: ```shell export PYOQS_VERSION=0.16.0 # install a specific liboqs release diff --git a/RELEASE.md b/RELEASE.md index 9d544cb..f42c0fa 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -1,16 +1,29 @@ -# liboqs-python version 0.16.0 +# liboqs-python version 0.16.0.1 --- -# Added in version 0.16.0 +This is a maintenance release of liboqs-python 0.16.0 that fixes a security +issue. It is still built for liboqs 0.16.0. All users of liboqs-python +0.10.0 through 0.16.0 who rely on liboqs being installed automatically +should upgrade. -- Updated to liboqs 0.16.0. -- Added the `PYOQS_VERSION` environment variable to override the liboqs - release that is installed automatically at runtime. -- Fixed the Windows shared library lookup to search for both `oqs.dll` and - `liboqs.dll`. -- Fixed a `StatefulSignature` segfault when liboqs is built without stateful - signature key generation support. +# Security fix in version 0.16.0.1 + +- **Shell command injection in automatic liboqs installation** + ([GHSA-pw23-r5gj-42g8](https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8)). + When liboqs was not found at import time, liboqs-python built it by running + git and CMake through a shell, so shell metacharacters in `PYOQS_VERSION`, + `OQS_INSTALL_PATH`, `HOME`, or `TMPDIR` could execute arbitrary commands. + These commands now run without a shell, and `PYOQS_VERSION` is validated. + +# Other changes in version 0.16.0.1 + +- Fixed automatic installation of liboqs release candidates (e.g., + `0.16.0-rc1`) and install paths that contain spaces. +- Added support for the ML-DSA external-mu variants when liboqs provides them + (they are not in liboqs 0.16.0). +- Added installation instructions for Windows and Raspberry Pi. +- Releases are now published to PyPI automatically. ## About @@ -34,9 +47,9 @@ See in particular limitations on intended use. ## Release notes -This release of liboqs-python was released on July 23, 2026. Its release +This release of liboqs-python was released on TODO. Its release page on GitHub is -https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0. +https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0.1. --- diff --git a/pyproject.toml b/pyproject.toml index 48f102a..5177af0 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,7 +1,7 @@ [project] name = "liboqs-python" requires-python = ">=3.10" -version = "0.16.1-dev" +version = "0.16.0.1" description = "Python bindings for liboqs, providing post-quantum public key cryptography algorithms" authors = [ { name = "Open Quantum Safe project", email = "contact@openquantumsafe.org" }, From 83b9733dd4282e6fb5a1958de825cc1fa963f028 Mon Sep 17 00:00:00 2001 From: Douglas Stebila Date: Wed, 23 Sep 2026 11:13:27 -0400 Subject: [PATCH 2/2] Release date for 0.16.0.1 Co-Authored-By: Claude Opus 5.5 Signed-off-by: Douglas Stebila --- CHANGES.md | 2 +- RELEASE.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGES.md b/CHANGES.md index fbe2029..323cedf 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -1,4 +1,4 @@ -# Version 0.16.0.1 - TODO +# Version 0.16.0.1 - September 23, 2026 - Security fix: the automatic liboqs installation no longer runs commands through a shell, which allowed command injection via `PYOQS_VERSION` and diff --git a/RELEASE.md b/RELEASE.md index f42c0fa..f3f4532 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -47,7 +47,7 @@ See in particular limitations on intended use. ## Release notes -This release of liboqs-python was released on TODO. Its release +This release of liboqs-python was released on September 23, 2026. Its release page on GitHub is https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0.1.