Impact
A flaw in the certificate chain construction routine of the Bouncy Castle C# library causes a loop with no reachable exit condition. When the application requests a certificate chain for a key entry in a PKCS#12 file, the code follows issuer links without keeping track of already visited certificates. If the issuer chain contains a cycle, the loop never terminates, continuously consuming CPU and memory until an OutOfMemoryException is raised. The resulting denial of service can be observed when the method never returns, leaving the host unresponsive. The vulnerability is identified as a CWE-835 loop with unreachable exit condition.
Affected Systems
Legion of the Bouncy Castle Inc. provides the bc‑csharp library. Versions prior to 2.7.0 are affected. Any .NET application that loads a PKCS#12 file and requests a certificate chain from bc‑csharp using these versions is vulnerable. The vulnerability was discovered in the bouncy castle csharp repository commit 1b8fad04.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Attackers must be able to supply a crafted PKCS#12 file to an application utilizing the vulnerable library; this is typically a local or controlled file input scenario. Based on the description, the likely attack vector is local file supply, but an application that accepts remote PKCS#12 uploads would also be at risk. Successful exploitation results in denial of service, with CPU and memory resources drained until the process throws an OutOfMemoryException. The fix requires upgrading the library version.
OpenCVE Enrichment