Bug 2544958 (CVE-2026-17508)
| Summary: | CVE-2026-17508 bouncycastle: bouncycastle-fips: Bouncy Castle: Denial of Service via unbounded key derivation cost parameters | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Bouncy Castle. Several password-based key derivation functions (KDF) process cost parameters directly from untrusted input without enforcing upper bounds. An attacker can exploit this vulnerability by supplying crafted input containing excessively high cost parameters, forcing the system to allocate substantial CPU or memory resources before verifying cryptographic integrity. This excessive resource consumption can result in a Denial of Service (DoS).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2545166, 2545167 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-10-02 07:53:39 UTC
|