Description
Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments, because the reassembly buffer for each incoming handshake message was allocated at the 24-bit length declared in the fragment header, without the check against the peer's maximum handshake message size that TLS already applied. A fragment carrying no payload can force an allocation of almost 16 MB, for each of up to 16 pending messages per handshake, before the handshake is authenticated. DTLS servers and DTLS clients are both affected; TLS is not.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The flaw occurs when the DTLS handshake reassembler allocates a buffer based on a 24‑bit length field from the fragment header without validating it against the maximum handshake message size enforced by TLS. This allows a remote, unauthenticated attacker to send crafted handshake fragments that can reserve nearly 16 MB per fragment; with up to 16 pending messages the library can consume over 256 MB of memory before authentication succeeds, leading to a denial of service.

Affected Systems

The Bouncy Castle (bc‑csharp) library is affected in all releases prior to 2.7.0. Both DTLS clients and servers built with this library are impacted; native TLS implementations are not. The security advisory provides commits that resolve the issue.

Risk and Exploitability

The CVSS score of 8.7 indicates High severity. No EPSS score is available and the flaw is not listed in the CISA KEV catalog, but the attack requires only initiating a DTLS handshake and sending maliciously sized fragments before authentication. Once exploited, the denial of service can collapse application availability or exhaust host memory.

Generated by OpenCVE AI on October 2, 2026 at 09:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Bouncy Castle .NET library to 2.7.0 or later
  • If an upgrade is not immediately possible, disable DTLS support or replace the library with one that validates handshake sizes before allocation
  • Configure network or application limits to reject DTLS fragments that exceed acceptable sizes or set memory limits for DTLS processing

Generated by OpenCVE AI on October 2, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments, because the reassembly buffer for each incoming handshake message was allocated at the 24-bit length declared in the fragment header, without the check against the peer's maximum handshake message size that TLS already applied. A fragment carrying no payload can force an allocation of almost 16 MB, for each of up to 16 pending messages per handshake, before the handshake is authenticated. DTLS servers and DTLS clients are both affected; TLS is not.
Title DTLS handshake reassembler allocates buffer from unchecked 24-bit length
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T06:57:21.718Z

Reserved: 2026-07-16T23:48:46.075Z

Link: CVE-2026-63566

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T07:16:36.973

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value