Bug 2510255 (CVE-2026-12852)

Summary: CVE-2026-12852 bouncycastle: Bouncy Castle for Java: Denial of Service via MLS wire decoder
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, anthomas, ant, anujha, aschwart, asoldano, aszczucz, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, bstansbe, cescoffi, cmah, dandread, dbruscin, dfreiber, dkreling, dlofthou, drichtar, drow, dschmidt, eaguilar, ebaron, ehelms, ehugonne, ewittman, fmariani, fmongiar, ggainey, gmalinko, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jburrell, jbuscemi, jlanda, jmartisk, jmatsuok, jnethert, jpasqual, jtolenti, juwatts, jwon, kshier, kvanderr, lthon, manderse, mcarlett, mdellweg, mhulan, mosmerov, mposolda, msvehla, nipatil, nmoumoul, nwallace, olubyans, osousa, pantinor, pberan, pcreech, pesilva, pgallagh, pjindal, pmackay, probinso, rchan, rguimara, rhel-process-autobot, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sbiarozk, sdawley, simaishi, smallamp, ssilvert, stcannon, sthorger, tcunning, teagle, thjenkin, tmalecek, tqvarnst, vdosoudi, vkumar, vmuzikar, watson-tool-maintainers, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this by providing a specially crafted message to the MLS wire decoder. The decoder allocates an attacker-declared opaque length without first performing a bounds check. This can lead to excessive memory allocation, resulting in a Denial of Service (DoS) for the application.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-03 04:01:22 UTC
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.