Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9092

Опубликовано: 16 авг. 2025
Источник: redhat
CVSS3: 1.8

Описание

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientsbcpg-jdk18onFix deferred
AMQ Clientsbcpkix-jdk15onFix deferred
AMQ Clientsbcpkix-jdk18onFix deferred
AMQ Clientsbcprov-jdk15onFix deferred
AMQ Clientsbcprov-jdk18onFix deferred
AMQ Clientsbctls-jdk15onFix deferred
AMQ Clientsbcutil-jdk15onFix deferred
AMQ Clientsbcutil-jdk18onFix deferred
Cryostat 4bcpkix-jdk18onFix deferred
Cryostat 4bcprov-jdk18onFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2388912org.bouncycastle: Bouncycastle Resource Exhaustion

1.8 Low

CVSS3

Связанные уязвимости

nvd
3 месяца назад

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

github
3 месяца назад

Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability

1.8 Low

CVSS3