Description
Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.
Published: 2026-10-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU exhaustion
Action: Immediate Patch
AI Analysis

Impact

A loop in the PKCS#12 key derivation routine of Legion of the Bouncy Castle Inc. bc‑csharp fails to exit when the iteration count is zero or negative, causing the loop to run through the full 32‑bit counter space. This results in extreme CPU usage and a denial of service. The flaw is a classic uncontrolled loop condition. The associated CWE is 835.

Affected Systems

Legion of the Bouncy Castle Inc. bc‑csharp versions prior to 2.7.0.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity with substantial impact on availability. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker who can supply a crafted PKCS#12 (PFX) file or a PKCS#8 encrypted private key that uses a PKCS#12 password‑based encryption algorithm. An application that processes such files without validation will execute the derivation loop until the counter wraps around, consuming CPU resources for roughly 2^32 iterations and effectively starving the system.

Generated by OpenCVE AI on October 2, 2026 at 09:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Legion of the Bouncy Castle Inc. bc‑csharp to version 2.7.0 or later where the loop condition bug is fixed.
  • Before upgrading, filter or reject PKCS#12 files with an iteration count of zero or negative to prevent livelock scenarios.
  • Configure application resource constraints or CPU throttling for cryptographic operations to limit the impact of potential denial‑of‑service attacks.

Generated by OpenCVE AI on October 2, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.
Title PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count
Weaknesses CWE-835
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:06:31.876Z

Reserved: 2026-07-16T23:50:45.118Z

Link: CVE-2026-63575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:02.643

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:15:08Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')