Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58063

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

A flaw was found in Bouncy Castle for Java. A remote attacker can exploit this vulnerability by providing a specially crafted BCFKS keystore file that specifies an unbounded Key Derivation Function (KDF) cost. This can lead to a Denial of Service (DoS) as the system attempts to process the file, consuming excessive resources and becoming unresponsive.

Отчет

Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. Loading a BCFKS keystore honors an unbounded Key Derivation Function (KDF) cost from the untrusted file, so loading a crafted keystore forces excessive computation and a denial of service. Exploitation requires the application to load an attacker-supplied BCFKS keystore file. Note: Red Hat rates this Important (CVSS v3 7.5, A:H) versus the upstream CVEORG v4 score of 5.3 (Moderate, A:L).

Меры по смягчению последствий

Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bc-fips 1.0.2.7/2.0.2/2.1.3) once available for the affected product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientsbcprov-jdk15onNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyAffected
Red Hat Enterprise Linux 9resteasyAffected
Red Hat JBoss Enterprise Application Platform 7bcprov-jdk15onWill not fix
Red Hat Single Sign-On 7bcprov-jdk15onAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510238org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Denial of Service via unbounded KDF cost in BCFKS keystore load

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

CVSS3: 5.3
nvd
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

CVSS3: 5.3
debian
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unb ...

CVSS3: 5.3
github
около 2 месяцев назад

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

suse-cvrf
около 2 месяцев назад

Security update for bouncycastle

7.5 High

CVSS3