CyberRota Analysis
AI-GeneratedThe vulnerability allows an attacker to exploit the PKCS#12 keystore loading process in affected versions of the Bouncy Castle library, leading to potential denial of service through CPU exhaustion by supplying a specially crafted PKCS#12 file with an excessively high iteration count. This flaw arises from the lack of limits on resource allocation during key derivation, which can be triggered before validating the file's integrity. Organizations using the Bouncy Castle library, particularly those handling sensitive cryptographic operations, should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file's MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.