Description
Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Patch
AI Analysis

Impact

Memory allocation occurs during HSS public key and signature parsing. An attacker can supply a public key with an excessive level count that is not limited to the RFC‑8554 maximum of eight. The code then allocates an array with one entry per level, potentially consuming about 17 GB of memory or causing an OutOfMemoryException. This results in a denial of service on the system performing the verification.

Affected Systems

Legion of the Bouncy Castle Inc. bc‑csharp, versions prior to 2.7.0. Any application using the library and parsing HSS signatures is impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated attacker who can supply both a malicious HSS public key and a signature, leading to memory exhaustion and application failure. The flaw exploits unchecked memory allocation (CWE‑789).

Generated by OpenCVE AI on October 2, 2026 at 08:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade bc‑csharp to version 2.7.0 or later to receive the fixed level‑count validation.
  • If upgrading immediately is not feasible, validate the parsed public key’s level count to ensure it does not exceed eight before proceeding with signature verification.
  • Restrict or monitor the use of HSS signatures so that only trusted internal inputs are processed to reduce the risk of triggering the memory allocation flaw.

Generated by OpenCVE AI on October 2, 2026 at 08:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.
Title Unbounded HSS public key level count allows huge array allocation during signature verification
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:10:34.017Z

Reserved: 2026-09-30T23:01:10.053Z

Link: CVE-2026-103603

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:00.837

Modified: 2026-10-02T08:17:00.837

Link: CVE-2026-103603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value