Описание
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-12803
- https://github.com/bcgit/bc-java/commit/697794413ebf7bc5e3fce609a707826ba52981af
- https://github.com/bcgit/bc-java/commit/7d79aa76e984da85f2a541cae8ba2ae56e1713bc
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9012803
- https://github.com/bcgit/bc-java/wiki/CVE-2026-12803
Связанные уязвимости
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bi ...