CyberRota Analysis
AI-GeneratedThe vulnerability affects the Pkcs12Store.GetCertificateChain method in the Bouncy Castle library prior to version 2.7.0, allowing an attacker to exploit crafted PKCS#12 files to create a denial of service condition. This occurs due to a loop with an unreachable exit condition that consumes CPU and memory resources until an OutOfMemoryException is triggered, particularly when certificates with cyclic issuer links are processed. Organizations using this library for cryptographic operations should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry's certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other's public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.