Bug 2390278 (CVE-2025-9341) - CVE-2025-9341 org.bouncycastle/bc-fips: Garbage collection can delay for AES CBC Native support, resulting in heap exhaustion
Summary: CVE-2025-9341 org.bouncycastle/bc-fips: Garbage collection can delay for AES ...
Keywords:
Status: NEW
Alias: CVE-2025-9341
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-08-22 10:01 UTC by OSIDB Bzimport
Modified: 2025-08-31 18:38 UTC (History)
21 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-08-22 10:01:17 UTC
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java.

This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0.


Note You need to log in before you can comment on or make changes to this bug.