天下漏洞,尽知其名
MEDIUM

CVE-2026-63575 Bouncy Castle bc-csharp PKCS#12 密钥派生拒绝服务漏洞

影响攻击者可通过构造恶意 PKCS#12 文件导致 CPU 耗尽拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle bc-csharp 的 PKCS#12 密钥派生组件 Pkcs12ParametersGenerator 存在循环退出条件不可达问题。当迭代次数为 0 或负数时,派生循环会绕行约 2^32 次才结束,导致处理被长时间占用。攻击者只需提供一个恶意 PFX 文件或使用 PKCS#12 口令加密算法的 PKCS#8 加密私钥即可触发。

影响范围

Bouncy Castle bc-csharp

Legion of the Bouncy Castle Inc. bc-csharp 2.7.0 之前的版本。

漏洞详情

该漏洞属于拒绝服务类型,成因是密钥派生循环的终止条件为计数器等于迭代次数,当迭代次数为 0 或负数时无法正常退出,需绕行约 2^32 次。攻击者可通过构造迭代次数为负的 MacData 的 PFX 文件,或提供使用 PKCS#12 口令加密算法的 PKCS#8 加密私钥来触发。实测一个 75 字节的恶意 PFX 文件即可使 Pkcs12Store.Load 持续繁忙数分钟。

利用条件与风险

利用前提是目标应用解析攻击者可控的 PKCS#12 或 PKCS#8 文件,无需认证即可造成 CPU 资源耗尽,实战中可导致服务不可用。

修复建议

升级至 bc-csharp 2.7.0 或更高版本。临时缓解措施包括限制上传文件大小与解析超时、对不可信 PKCS#12/PKCS#8 输入进行隔离处理,暂无其他公开信息。

原始情报

Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.