Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20627-1

Опубликовано: 24 апр. 2026
Источник: suse-cvrf

Описание

Security update for bouncycastle

This update for bouncycastle fixes the following issues:

  • Update to version 1.84:
  • CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225).
  • CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java (bsc#1262226).
  • CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232).
  • CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228).
  • CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM (bsc#1262227).

Список пакетов

openSUSE Leap 16.0
bouncycastle-1.84-160000.1.1
bouncycastle-javadoc-1.84-160000.1.1
bouncycastle-jmail-1.84-160000.1.1
bouncycastle-mail-1.84-160000.1.1
bouncycastle-pg-1.84-160000.1.1
bouncycastle-pkix-1.84-160000.1.1
bouncycastle-tls-1.84-160000.1.1
bouncycastle-util-1.84-160000.1.1

Описание

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. GOSTCTR implementation unable to process more than 255 blocks correctly. This issue affects BC-JAVA: from 1.59 before 1.84.


Затронутые продукты
openSUSE Leap 16.0:bouncycastle-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-javadoc-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-jmail-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-mail-1.84-160000.1.1

Ссылки

Описание

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.84.


Затронутые продукты
openSUSE Leap 16.0:bouncycastle-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-javadoc-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-jmail-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-mail-1.84-160000.1.1

Ссылки

Описание

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-JAVA: from 1.74 before 1.84.


Затронутые продукты
openSUSE Leap 16.0:bouncycastle-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-javadoc-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-jmail-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-mail-1.84-160000.1.1

Ссылки

Описание

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11.


Затронутые продукты
openSUSE Leap 16.0:bouncycastle-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-javadoc-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-jmail-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-mail-1.84-160000.1.1

Ссылки

Описание

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.84.


Затронутые продукты
openSUSE Leap 16.0:bouncycastle-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-javadoc-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-jmail-1.84-160000.1.1
openSUSE Leap 16.0:bouncycastle-mail-1.84-160000.1.1

Ссылки
Уязвимость openSUSE-SU-2026:20627-1