Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcmw-xv23-7hqq

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.7

Описание

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers.

This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C.

This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.

Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers.

This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C.

This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.

Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.

EPSS

Процентиль: 1%
0.001
Низкий

1.7 Low

CVSS4

Дефекты

CWE-787

Связанные уязвимости

ubuntu
около 1 месяца назад

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.

nvd
около 1 месяца назад

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.

debian
около 1 месяца назад

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. ...

EPSS

Процентиль: 1%
0.001
Низкий

1.7 Low

CVSS4

Дефекты

CWE-787