CVE-2026-63575
Pętla z nieosiągalnym warunkiem zakończenia w Bouncy Castle prowadzi do odmowy usługi przez wyczerpanie CPU.
Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 08:17:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 20:17:03 UTC |
- https://github.com/bcgit/bc-csharp/commit/0c7a6dfd64c4a479577e35a728a766721b79aba7 (91579145-5d7b-4cc5-b925-a0262ff19630)
- https://github.com/bcgit/bc-csharp/commit/7c0ed15f9783c9595b1a53f3900136461fd944f4 (91579145-5d7b-4cc5-b925-a0262ff19630)
- https://github.com/bcgit/bc-csharp/wiki/CVE-2026-63575 (91579145-5d7b-4cc5-b925-a0262ff19630)