Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5598

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA core. A covert timing channel vulnerability, caused by non-constant time comparisons, risks the leakage of private keys in the FrodoKEM implementation. An unauthenticated, remote attacker can potentially exploit this timing discrepancy to gain unauthorized access to sensitive cryptographic information.

Отчет

To exploit this issue, an unauthenticated attacker needs to send highly specific, malformed ciphertexts to the target server. These payloads are used to interact with the private key of the server in a way that the vulnerable, non-constant time code paths are triggered during the verification step. An attack typically requires sending a large volume of these requests to perform statistical analysis on the resulting timing variations, increasing its complexity. The primary security impact of this vulnerability is the potential leakage of private keys associated with the FrodoKEM implementation. This can compromise encrypted communications or authentication mechanisms.

Меры по смягчению последствий

To mitigate this vulnerability, implement aggressive rate limiting and anomaly detection, specifically looking for unusual, high-frequency cryptographic handshake failures or anomalous traffic patterns targeting endpoints that handle key exchanges in the network logs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4bcprov-jdk18onNot affected
OpenShift Developer Tools and ServicesjenkinsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
Red Hat AMQ Broker 7bcprov-jdk15onNot affected
Red Hat AMQ Broker 7bcprov-jdk18onNot affected
Red Hat AMQ Clientsbcprov-jdk15onNot affected
Red Hat AMQ Clientsbcprov-jdk18onNot affected
Red Hat build of Apache Camel 4 for Quarkus 3bcprov-jdk18onNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=2458635bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVSS3: 7.5
nvd
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVSS3: 7.5
debian
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc ...

github
4 месяца назад

Bouncy Castle Has Covert Timing Channel Vulnerability

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость файла FrodoEngine.Java криптографической библиотеки для платформы Java Bouncy Castle, позволяющая нарушителю раскрыть защищаемую информацию

7.5 High

CVSS3