The algorithm works for (v, o, m)-UOV instances for which the following sum is non-positive


Parameter sets not in this list are not affected.
Keep an eye out on eprint the coming month for the full analysis.
Kind regards,
Lars
Dear all,
As a follow-up on my previous post about UOV, MAYO, and SNOVA, the paper with the full analysis is now available on ePrint, and I am happy to share it with you: https://eprint.iacr.org/2025/1143
As pointed out to me by Ray Perlner and Maxime Bros, the UOV-systems in SNOVA are not generic and this might cause problems for the algorithm. I agree with them and think more research is necessary to correctly predict the rank of the matrix M in the case of SNOVA. This means that the algorithm might still work, but it is unclear for what minimal o' <= o, if any. Therefore, I will retract my complexity claim on SNOVA for now.
The updated table of complexities can be found below:

I am happy to answer any questions or comments that you may have, so feel free to contact me.
Kind regards, Lars