Impact
Memory allocation occurs during HSS public key and signature parsing. An attacker can supply a public key with an excessive level count that is not limited to the RFC‑8554 maximum of eight. The code then allocates an array with one entry per level, potentially consuming about 17 GB of memory or causing an OutOfMemoryException. This results in a denial of service on the system performing the verification.
Affected Systems
Legion of the Bouncy Castle Inc. bc‑csharp, versions prior to 2.7.0. Any application using the library and parsing HSS signatures is impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated attacker who can supply both a malicious HSS public key and a signature, leading to memory exhaustion and application failure. The flaw exploits unchecked memory allocation (CWE‑789).
OpenCVE Enrichment