CVE-2026-63572 Bouncy Castle bc-csharp PKCS#12 资源耗尽拒绝服务漏洞
影响攻击者可构造恶意 PFX 文件导致 CPU 耗尽拒绝服务
Legion of the Bouncy Castle Inc. 的 bc-csharp 库在加载 PKCS#12(PFX)密钥库时未对资源分配设置上限。攻击者可通过在 MacData 或加密 SafeContents、shrouded key bag 的 PBE 参数中指定接近 2^31 的迭代次数,触发大量 CPU 计算,造成拒绝服务。该问题影响 2.7.0 之前的版本,Pkcs12Utilities.ConvertToDefiniteLength 同样受影响。
影响范围
bc-csharp 2.7.0 之前的版本。具体受影响版本范围暂无更详细的公开信息。
漏洞详情
漏洞类型为不受限制的资源分配(CWE-770)。成因是 Pkcs12Store.Load 在解析 PKCS#12 文件时直接采用文件中的迭代次数,未设置上限,且在 MAC 或密码校验之前就执行密钥派生运算。攻击者只需提供一个迭代次数接近 2^31 的 PFX 文件,即可让解析过程长时间占用 CPU,导致服务不可用。
利用条件与风险
利用前提是目标应用使用受影响版本的 bc-csharp 解析攻击者可控的 PKCS#12 文件,无需认证即可触发。实战中可造成服务线程阻塞或 CPU 资源耗尽,形成拒绝服务。
修复建议
建议升级到 bc-csharp 2.7.0 或更高版本。临时缓解措施包括:在解析 PKCS#12 文件前限制文件来源与大小、对迭代次数设置合理上限,或对解析操作设置超时与资源隔离。暂无其他公开信息。
Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file to cause a denial of service through CPU exhaustion via an iteration count close to 2^31 in the file’s MacData or in the PBE parameters of an encrypted SafeContents or shrouded key bag, because the counts are taken from the file without an upper bound and the key derivation runs before the MAC or the password can be checked. A zero or negative count is covered by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength is also affected.