天下漏洞,尽知其名
MEDIUM

CVE-2026-17508 Bouncy Castle Java 拒绝服务漏洞

影响攻击者可用小输入触发超量计算,导致服务拒绝

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle for Java 1.86 之前版本中,多个基于口令的密钥派生入口在派生密钥前未对来自不可信输入的代价参数做上限约束。攻击者只需提供很小的输入,即可迫使程序执行任意量的计算,从而造成拒绝服务。

影响范围

Bouncy Castle Java

Bouncy Castle for Java 1.86 之前的版本,涉及 RFC 9579 PBMAC1、PKCS#8/PKCS#12 scrypt 代价校验、JCA PBKDF2 提供者及 OpenSSH v1 私钥 bcrypt 轮数等路径。

漏洞详情

漏洞类型为不受控制的资源消耗(拒绝服务)。成因是 PBMAC1 的 PBKDF2 迭代次数与派生密钥长度、scrypt 并行参数 p、PBKDF2 提供者参数以及 OpenSSH v1 私钥中的 bcrypt 轮数均直接取自待处理数据且未设上限。攻击者构造恶意参数即可在口令或完整性校验拒绝之前消耗大量 CPU 或内存。

利用条件与风险

利用前提是应用使用受影响版本处理来自不可信来源的密钥派生参数或加密私钥;实战中可被用于耗尽服务端 CPU/内存,造成服务不可用。

修复建议

升级到 Bouncy Castle for Java 1.86 或更高版本,该版本在派生前对参数进行边界限制,并可通过 org.bouncycastle.openssh.max_rounds 配置 OpenSSH 轮数上限;暂无公开信息说明其他临时缓解措施。

原始情报

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key’s own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.max_rounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).