You would get cube root speedup instead of sqrt for a collision (birthday attack), or sqrt instead of brute force for a preimage. So SHA256 is secure from preimage attacks even with a quantum computer, and gives 2^80 protection against collisions. SHA-2/384 would be sufficient for 128-bit security against collisions.