Bug 2510259 (CVE-2026-12816)

Summary: CVE-2026-12816 org.bouncycastle/bcprov-jdk15on: Bouncy Castle for Java: Message Authentication Code (MAC) forgery due to a length-dependent Key Derivation Function (KDF) split
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, ant, anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, cescoffi, csuconic, dbruscin, dfreiber, dlofthou, drichtar, drow, dschmidt, eglynn, ehelms, ehugonne, ewittman, fmariani, fmongiar, gbenhaim, ggainey, gmalinko, gsmet, gtully, istudens, ivassile, iweiss, janstey, jburrell, jjoyce, jlanda, jmartisk, jnethert, jpasqual, jpretori, jschluet, jsherman, juwatts, jwon, kshier, kvanderr, lhh, manderse, mburns, mcarlett, mdellweg, mgarciac, mhulan, mosmerov, mposolda, msvehla, nipatil, niyer, nmoumoul, nwallace, olubyans, osousa, ozzy, pantinor, pberan, pcreech, pdelbell, pesilva, pjindal, pmackay, rchan, rgemmell, rgodfrey, rguimara, rhel-process-autobot, rkubis, rmartinc, rstancel, rstepani, sbiarozk, sdawley, simaishi, smallamp, ssilvert, stcannon, sthorger, tbish, tcunning, thjenkin, tlavocat, tmalecek, twaugh, varjain, vdosoudi, vkumar, vmuzikar, watson-tool-maintainers, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Bouncy Castle for Java. This vulnerability allows for Message Authentication Code (MAC) forgery in the IESEngine stream-mode. The issue arises from a length-dependent Key Derivation Function (KDF) split, which an attacker could exploit to bypass integrity checks. This could lead to unauthorized manipulation of data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-03 04:01:35 UTC
In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.