CVE-2026-103603

⚪ Do wiadomości

Przydzielanie pamięci z nadmierną wartością w Bouncy Castle prowadzi do odmowy usługi.

CVSS
0.0
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-10-02 08:17:00 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:17:00 UTC
Referencje