天下漏洞,尽知其名
MEDIUM

CVE-2026-97873 Bouncy Castle Java 拒绝服务漏洞

影响攻击者可构造恶意输入触发超量密钥派生计算,导致服务拒绝

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle for Java 在 1.86 之前的版本中,其 JCA provider 的旧版 PBES1(PKCS#5 scheme 1)与 PKCS#12 PBE 系列在进行基于口令的密钥派生时,直接采用来自不可信输入的迭代次数且未做上限约束。攻击者只需提供很小的输入即可迫使系统执行任意大的计算量,从而造成拒绝服务。该问题同样影响 Bouncy Castle for Java LTS 2.73.13 之前的版本。

影响范围

Bouncy Castle for Java

Bouncy Castle for Java 1.86 之前版本;Bouncy Castle for Java LTS 2.73.13 之前版本。

漏洞详情

漏洞类型为拒绝服务(资源耗尽)。成因是 PKCS12PBE、PBKDF1 等 AlgorithmParameters 实现接受编码参数中的任意迭代次数,并用 intValue() 对超出 int 范围的值进行截断,随后各 Cipher、Mac、SecretKeyFactory 按该次数执行密钥派生。攻击者可通过构造恶意 PKCS12PBEParams 或 PBEParameter,或借助其他 provider 解码的参数(如 EncryptedPrivateKeyInfo.getKeySpec() 解密 PKCS#12 PBE 保护的私钥)来注入超大迭代次数。

利用条件与风险

利用前提是应用会解析或处理攻击者可控的 PBE 参数或加密数据,无需认证即可触发。实战中可导致 CPU 长时间占用、服务不可用,属于中危拒绝服务风险。

修复建议

升级至 Bouncy Castle for Java 1.86 或更高版本,LTS 用户升级至 2.73.13 或更高版本。修复后参数解析与密钥派生会拒绝负数或超过 org.bouncycastle.pbe.max_iteration_count(默认 10,000,000)的迭代次数,并拒绝超出 int 范围的值;临时缓解可设置该属性限制迭代上限。

原始情报

In Bouncy Castle for Java before 1.86, the raw JCA provider’s legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it, so a small input could dictate an arbitrary amount of work before anything could be verified. The AlgorithmParameters implementations (PKCS12PBE and its object identifier aliases, and PBKDF1) accepted any count from an encoded PKCS12PBEParams or PBEParameter, narrowing a value beyond the int range with intValue(), and every Cipher, Mac and SecretKeyFactory in these families derived with whatever count it was given, including one decoded by another provider’s AlgorithmParameters, as when javax.crypto.EncryptedPrivateKeyInfo.getKeySpec() decrypts a PKCS#12 PBE-protected private key with BC. Both the parameter parse and the derivations now reject a negative or over-limit count under the org.bouncycastle.pbe.max_iteration_count property (default 10,000,000) that already bounded PBKDF2 (CVE-2026-17508), and the parse rejects a count beyond the int range rather than narrowing it. This issue also affects Bouncy Castle for Java LTS before 2.73.13.