天下漏洞,尽知其名
MEDIUM

CVE-2026-71892 Bouncy Castle CMS 密钥大小验证绕过漏洞

影响攻击者可绕过密钥大小校验,使不符合预期长度的内容加密密钥被接受

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle for Java 1.86 之前版本中,CMS 密钥传输接收方的可选密钥大小校验(JceKeyTransRecipient.setKeySizeValidation(true))在使用 RFC 9709 内容加密密钥派生(id-alg-cek-hkdf-sha256)时不会执行。代码将加密密钥字节数组与 ASN1ObjectIdentifier 直接比较,该比较恒为 false,导致校验落入外层包装 OID 的密钥大小查询,而该 OID 表示密钥派生结构、没有注册密钥大小,最终整个大小比较被跳过。

影响范围

Bouncy Castle

Bouncy Castle for Java 1.86 之前的版本,涉及使用 CMS 密钥传输并结合 RFC 9709 HKDF 内容加密密钥派生的场景。具体受影响版本范围以官方公告为准。

漏洞详情

漏洞类型为安全特性绕过(密钥大小验证失效)。成因是分支判断中把 byte[] 与 ASN1ObjectIdentifier 做比较,逻辑恒为假,使代码走错分支并最终跳过密钥大小检查。利用方式是构造密钥传输的 EnvelopedData 或 AuthEnvelopedData,使经 HKDF 派生的内容加密密钥长度与所声明的内容加密算法密钥长度不一致,即使显式开启校验也会被接受。

利用条件与风险

需要接收并处理攻击者构造的 CMS 消息,且应用显式启用了 setKeySizeValidation(true)。实战中会导致 API 提供的唯一密钥大小强制机制被静默绕过,削弱加密强度保障。

修复建议

升级到 Bouncy Castle for Java 1.86 或更高版本,该版本已修正接收方的算法分派逻辑。若无法立即升级,应避免依赖该可选校验,并在应用层自行校验解密密钥长度。暂无其他公开缓解信息。

原始情报

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption key derivation (id-alg-cek-hkdf-sha256). The branch that should have selected the actual content-encryption algorithm carried in the key derivation AlgorithmIdentifier’s parameters compared the encrypted-key byte array against the id-alg-cek-hkdf-sha256 object identifier, a comparison between a byte array and an ASN1ObjectIdentifier that is false for every possible input, so the check fell through to a key-size lookup on the outer wrapper OID. That OID identifies a key-derivation construction rather than a cipher and has no registered key size, so the size comparison was skipped entirely. A key-transport EnvelopedData or AuthEnvelopedData whose transported, HKDF-derived content-encryption key did not match the key size of the advertised content-encryption algorithm was therefore accepted even with validation explicitly enabled, silently defeating the only mechanism the API offers for enforcing recovered key size. The recipient now dispatches on the content-encryption AlgorithmIdentifier’s algorithm OID, so validation checks the recovered key against the inner content-encryption algorithm. Messages with a matching key size, non-HKDF messages, and recipients that do not enable validation are unaffected. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).