Same issue with signature malleability as with Ed25519 and apparently OpenSSL doesn't even explicitly verify that the most significant 10 bits are all zero.