Description
Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted OpenPGP public key, certificate or signature to cause a denial of service (OutOfMemoryException or memory exhaustion in the parsing process) via a subpacket header using the five-octet length form, because the declared length was used to size the subpacket buffer with no upper bound and without being compared with the size of the enclosing subpacket area or packet, so a few bytes of input could demand an allocation of up to about 2 GB before any subpacket data was read.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A flaw in the OpenPGP signature and user attribute subpacket parsers of the bc‑csharp library uses a five‑octet length field without any upper bound. This allows a remote, unauthenticated attacker who can supply a crafted OpenPGP key, certificate or signature to request a buffer allocation of up to approximately 2 GB before any packet data is read, causing an OutOfMemoryException or system memory exhaustion and leading to application crash or denial of service. The vulnerability does not provide any path for code execution, privilege escalation, or data exfiltration.

Affected Systems

Legion of the Bouncy Castle Inc. bc‑csharp, a .NET library used for OpenPGP operations, is affected in all releases prior to version 2.7.0. Users of the library who process external OpenPGP data are exposed.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity denial‑of‑service risk. The EPSS score is not available, but the lack of an upper bound on the allocation makes exploitation straightforward as long as the library parses untrusted input. The issue is not listed in CISA’s KEV catalog, yet the potential for memory exhaustion is significant in environments where the library handles arbitrary input without safeguards. Attackers need only supply malicious OpenPGP data; no additional privileges are required.

Generated by OpenCVE AI on October 2, 2026 at 09:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade bc‑csharp to version 2.7.0 or later to apply the official fix.
  • If upgrading immediately is not possible, wrap any OpenPGP parsing calls in a sandboxed environment with memory limits to prevent allocation of large buffers.
  • Implement application‑level validation that rejects any subpacket length values exceeding a safe threshold before invoking the library, effectively capping the allocation size.

Generated by OpenCVE AI on October 2, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted OpenPGP public key, certificate or signature to cause a denial of service (OutOfMemoryException or memory exhaustion in the parsing process) via a subpacket header using the five-octet length form, because the declared length was used to size the subpacket buffer with no upper bound and without being compared with the size of the enclosing subpacket area or packet, so a few bytes of input could demand an allocation of up to about 2 GB before any subpacket data was read.
Title Unbounded allocation from OpenPGP signature and user attribute subpacket lengths
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:06:00.965Z

Reserved: 2026-07-16T23:50:45.118Z

Link: CVE-2026-63574

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:02.477

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value