Impact
An unbounded iteration count in the PKMacBuilder verifier (PKMacBuilder) of the Legion of the Bouncy Castle Inc. bc-csharp library allows a remote unauthenticated attacker to trigger a denial of service through CPU exhaustion. By forging a CMP message or a CRMF certificate request whose PBMParameter declares a very large iteration count, the verifier performs hash iterations up to about 2^31. The library enforces a ceiling only when an explicit maximum is supplied via the PKMacBuilder(IPKMacPrimitivesProvider, int) constructor; otherwise the default constructors permit any count. The resulting CPU over‑utilisation can cause the hosting process to become unresponsive or crash, compromising availability.
Affected Systems
The affected product is the Bouncy Castle C# cryptographic library (bc-csharp) from Legion of the Bouncy Castle Inc. Any deployment using a version prior to 2.7.0 is vulnerable. Users of earlier releases that employ CMP or CRMF message verification via PKMacBuilder without specifying a custom maximum are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is not available, but the lack of a listed KEV status suggests no known exploitation at the time of reporting. An attacker can remotely supply a crafted message to any application that processes CMP or CRMF messages using the vulnerable library, without needing authentication. The main attack vector is an unauthenticated network request that includes a PBMParameter with an extreme iteration count, leading to excessive CPU usage and service disruption.
OpenCVE Enrichment