Описание
Security update for bouncycastle
This update for bouncycastle fixes the following issues:
- Update to version 1.84:
- CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225).
- CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java (bsc#1262226).
- CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232).
- CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228).
- CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM (bsc#1262227).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1262225
- SUSE Bug 1262226
- SUSE Bug 1262227
- SUSE Bug 1262228
- SUSE Bug 1262232
- SUSE CVE CVE-2025-14813 page
- SUSE CVE CVE-2026-0636 page
- SUSE CVE CVE-2026-3505 page
- SUSE CVE CVE-2026-5588 page
- SUSE CVE CVE-2026-5598 page
Описание
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. GOSTCTR implementation unable to process more than 255 blocks correctly. This issue affects BC-JAVA: from 1.59 before 1.84.
Затронутые продукты
Ссылки
- CVE-2025-14813
- SUSE Bug 1262225
Описание
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.84.
Затронутые продукты
Ссылки
- CVE-2026-0636
- SUSE Bug 1262226
Описание
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-JAVA: from 1.74 before 1.84.
Затронутые продукты
Ссылки
- CVE-2026-3505
- SUSE Bug 1262232
Описание
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11.
Затронутые продукты
Ссылки
- CVE-2026-5588
- SUSE Bug 1262228
Описание
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84.
Затронутые продукты
Ссылки
- CVE-2026-5598
- SUSE Bug 1262227