Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9092

Опубликовано: 16 авг. 2025
Источник: redhat
CVSS3: 1.8
EPSS Низкий

Описание

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

Uncontrolled Resource Consumption vulnerability has been discovered in the Legion of the Bouncy Castle Inc. Bouncy Castle for Java. In multi-JVM environments BC-FJA 2.1.0 could be found to create many library directories for the .so files required for native support, even though the files contained in the directories could have been shared. This could lead to server fragility, particularly in the case where it was difficult to identify which library directories were in use and which were not, with the subsequent strain on resources leading to service failure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4bcpkix-jdk18onFix deferred
Cryostat 4bcprov-jdk18onFix deferred
Cryostat 4bcutil-jdk18onFix deferred
Logging Subsystem for Red Hat OpenShiftbcmail-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcpg-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcpkix-jdk15onFix deferred
Logging Subsystem for Red Hat OpenShiftbcprov-jdk15onFix deferred
Red Hat AMQ Broker 7bcpkix-jdk15onFix deferred
Red Hat AMQ Broker 7bcpkix-jdk18onFix deferred
Red Hat AMQ Broker 7bcprov-jdk15onFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2388912org.bouncycastle: Bouncycastle Resource Exhaustion

EPSS

Процентиль: 4%
0.00147
Низкий

1.8 Low

CVSS3

Связанные уязвимости

nvd
около 1 года назад

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

github
около 1 года назад

Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability

EPSS

Процентиль: 4%
0.00147
Низкий

1.8 Low

CVSS3

Уязвимость CVE-2025-9092