Impact
The flaw occurs when the DTLS handshake reassembler allocates a buffer based on a 24‑bit length field from the fragment header without validating it against the maximum handshake message size enforced by TLS. This allows a remote, unauthenticated attacker to send crafted handshake fragments that can reserve nearly 16 MB per fragment; with up to 16 pending messages the library can consume over 256 MB of memory before authentication succeeds, leading to a denial of service.
Affected Systems
The Bouncy Castle (bc‑csharp) library is affected in all releases prior to 2.7.0. Both DTLS clients and servers built with this library are impacted; native TLS implementations are not. The security advisory provides commits that resolve the issue.
Risk and Exploitability
The CVSS score of 8.7 indicates High severity. No EPSS score is available and the flaw is not listed in the CISA KEV catalog, but the attack requires only initiating a DTLS handshake and sending maliciously sized fragments before authentication. Once exploited, the denial of service can collapse application availability or exhaust host memory.
OpenCVE Enrichment