Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-8885

Опубликовано: 12 авг. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.

A resource exhaustion flaw has been discovered in the Bouncy Castle for Java library. The flaw exists because there was no practical limit on the size of an encoded ASN.1 Object Identifier (OID), beyond the maximum size of an ASN1Object. While technically valid, this could be exploited by an attacker to create excessively large OIDs, which would cause uncontrolled memory consumption and lead to a denial of service (DoS) attack. In following the practice of other providers, we have adopted a limit of 4096 bytes on the size of an encoded identifier and a cap of 16385 characters on an identifier string.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4bcpkix-jdk18onFix deferred
Cryostat 4bcprov-jdk18onFix deferred
Cryostat 4bcutil-jdk18onFix deferred
Logging Subsystem for Red Hat OpenShiftbcmail-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcpg-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcpkix-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcprov-jdk15onFix deferred
Red Hat AMQ Broker 7bcpkix-jdk15onNot affected
Red Hat AMQ Broker 7bcpkix-jdk18onNot affected
Red Hat AMQ Broker 7bcprov-jdk15onNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2387790bouncycastle: Bouncy Castle denial of service parsing ASN.1 Object Identifiers

EPSS

Процентиль: 22%
0.00071
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
8 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.

nvd
8 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdenti... https://github.com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java . This issue affects BC Java: from 1.0 through 1.77; BC-FJA: from 1.0.0 through 1.0.2.5, from 2.0.0 through 2.0.1.

debian
8 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

github
8 месяцев назад

Bouncy Castle for Java on All (API modules) allows Excessive Allocation

EPSS

Процентиль: 22%
0.00071
Низкий

5.3 Medium

CVSS3