Impact
A flaw in the OpenPGP signature and user attribute subpacket parsers of the bc‑csharp library uses a five‑octet length field without any upper bound. This allows a remote, unauthenticated attacker who can supply a crafted OpenPGP key, certificate or signature to request a buffer allocation of up to approximately 2 GB before any packet data is read, causing an OutOfMemoryException or system memory exhaustion and leading to application crash or denial of service. The vulnerability does not provide any path for code execution, privilege escalation, or data exfiltration.
Affected Systems
Legion of the Bouncy Castle Inc. bc‑csharp, a .NET library used for OpenPGP operations, is affected in all releases prior to version 2.7.0. Users of the library who process external OpenPGP data are exposed.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity denial‑of‑service risk. The EPSS score is not available, but the lack of an upper bound on the allocation makes exploitation straightforward as long as the library parses untrusted input. The issue is not listed in CISA’s KEV catalog, yet the potential for memory exhaustion is significant in environments where the library handles arbitrary input without safeguards. Attackers need only supply malicious OpenPGP data; no additional privileges are required.
OpenCVE Enrichment