CyberRota Analysis
AI-GeneratedThe vulnerability affects the parsing of OpenPGP signatures and user attributes in Legion of the Bouncy Castle Inc. bc-csharp versions prior to 2.7.0, allowing remote, unauthenticated attackers to exploit excessive memory allocation. This can lead to denial of service through OutOfMemoryExceptions, as attackers can craft inputs that trigger massive memory allocations without proper bounds checking. Organizations utilizing this library for cryptographic operations should prioritize patching to mitigate potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted OpenPGP public key, certificate or signature to cause a denial of service (OutOfMemoryException or memory exhaustion in the parsing process) via a subpacket header using the five-octet length form, because the declared length was used to size the subpacket buffer with no upper bound and without being compared with the size of the enclosing subpacket area or packet, so a few bytes of input could demand an allocation of up to about 2 GB before any subpacket data was read.