CVE-2026-63578 Bouncy Castle bc-csharp 拒绝服务漏洞
影响攻击者可触发 CPU 耗尽导致拒绝服务
Bouncy Castle bc-csharp 在基于口令的私钥解密流程(PbeUtilities.GenerateCipherParameters)中未对资源分配设置上限。攻击者可通过提供迭代次数接近 2^31 的加密私钥(如 PKCS#8 EncryptedPrivateKeyInfo 或 ENCRYPTED PRIVATE KEY PEM 文件),使密钥派生在口令与数据校验之前执行,从而耗尽 CPU。
影响范围
受影响组件为 Legion of the Bouncy Castle Inc. 的 bc-csharp,2.7.0 之前的版本;具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为无限制资源分配(CWE-770),成因是算法参数中的迭代次数取自未认证的输入且没有上限,密钥派生又先于口令和数据校验执行。攻击者只需构造迭代次数接近 2^31 的加密私钥文件并诱导目标解析,即可让服务长时间占用 CPU。PKCS#5 PBES1/PBES2(PBKDF2)、PKCS#12 PBE 算法及 CMS 口令接收者(CmsPbeKey)均受影响。
利用条件与风险
利用前提是目标应用会解析攻击者可控的加密私钥或 CMS 口令接收者数据;实战中可造成服务响应缓慢或不可用,属于拒绝服务风险。
修复建议
建议升级到 bc-csharp 2.7.0 或更高版本;临时缓解措施为限制解析不可信加密私钥的入口,或对迭代次数设置上限,具体以官方公告为准。
Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply an encrypted private key, such as a PKCS#8 EncryptedPrivateKeyInfo or “ENCRYPTED PRIVATE KEY” PEM file, to cause a denial of service through CPU exhaustion via an iteration count close to 2^31, because the count is taken from the unauthenticated algorithm parameters without an upper bound and the key derivation runs before the password or the data can be checked. PKCS#5 PBES1 and PBES2 (PBKDF2), the PKCS#12 PBE algorithms and CMS password recipients (CmsPbeKey) are affected. Loading PKCS#12 files with Pkcs12Store is covered by CVE-2026-63572, and a zero or negative count with the PKCS#12 algorithms by CVE-2026-63575.