Description
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers.

This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C.



This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.



Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.
Published: 2026-07-16
Score: 1.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write that occurs in Bouncy Castle LTS’s native ARM SHA3 / SHAKE implementation when the restoreFullState routine processes a crafted encoded state. Based on the description, it is inferred that the attacker would need to supply such a crafted state to trigger the overflow, allowing the written data to overwrite adjacent memory. The flaw only manifests when the application accepts memoable SHA3 / SHAKE states that may come from untrusted sources, and the CVE description does not confirm any exploit for remote code execution.

Affected Systems

Affected products are Legion of the Bouncy Castle Inc.’s Bouncy Castle LTS bcprov‑lts8on running on ARM architectures. All releases from 2.73.0 up to and including 2.73.12.0 are vulnerable; the problematic code is fixed in 2.73.12.1 and later versions.

Risk and Exploitability

The CVSS score of 1.7 indicates a low base severity, and the EPSS of less than 1% shows a very low likelihood of active exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the exploit requires the attacker to supply a crafted state to the restoreFullState function, which typically occurs via user‑controlled input such as data received over a network or other external interface. Because the flaw results in an arbitrary memory write, it could compromise data integrity or cause a crash, but the CVE description does not confirm any exploit for remote code execution. The overall risk depends on whether the decryption routine is exposed to unauthenticated input.

Generated by OpenCVE AI on July 31, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to bcprov‑lts8on version 2.73.12.1 or later, which applies the size_t underflow fix.
  • If an upgrade cannot be performed immediately, ensure that any memoable SHA3 / SHAKE states fed into restoreFullState originate from trusted sources, or disable acceptance of such states entirely.
  • Place the library or the functions that process state data in a sandboxed or restricted process to limit the impact of any potential memory write and monitor the application for abnormal crashes.

Generated by OpenCVE AI on July 31, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-lts
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-lts

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C. This issue affects BC-LTS: from 2.73.0 before 2.73.12.1. Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.
Title Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 1.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:P/AU:N/R:A/V:D/RE:M/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-lts
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-07-17T13:12:39.282Z

Reserved: 2026-07-16T21:47:28.715Z

Link: CVE-2026-15997

cve-icon Vulnrichment

Updated: 2026-07-17T13:12:26.431Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:15:18Z

Weaknesses