CVE-2026-63570 Bouncy Castle bc-csharp 拒绝服务漏洞
影响攻击者可致应用无限循环并耗尽内存,造成拒绝服务
Bouncy Castle bc-csharp 2.7.0 之前版本的 Pkcs12Store.GetCertificateChain 方法存在循环退出条件不可达问题。当应用加载攻击者构造的 PKCS#12 文件并请求某密钥条目的证书链时,会陷入无限循环。
影响范围
Legion of the Bouncy Castle Inc. bc-csharp 2.7.0 之前版本。
漏洞详情
该漏洞属于无限循环导致的拒绝服务。构建证书链的循环仅在找不到签发者或证书自签时才停止,且不记录已访问的证书;同时跟随 AuthorityKeyIdentifier 链接时不校验签名。攻击者可构造两张证书,其 AuthorityKeyIdentifier 互相指向对方公钥,形成签发者环路,使循环永不终止。
利用条件与风险
利用前提是应用加载攻击者可控的 PKCS#12 文件并请求密钥条目的证书链。成功利用会导致调用永不返回,持续消耗 CPU 与内存直至抛出 OutOfMemoryException,造成拒绝服务。
修复建议
建议升级至 bc-csharp 2.7.0 或更高版本。临时缓解措施为不加载不可信的 PKCS#12 文件,或对相关调用设置超时与资源限制。
Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an application that loads it and requests a key entry’s certificate chain to cause a denial of service, in which the call never returns and consumes CPU and memory until an OutOfMemoryException, via certificates whose issuer links form a cycle, for example two certificates whose AuthorityKeyIdentifier extensions each identify the other’s public key. This happens because the chain-building loop stops only when no issuer is found or a certificate links to itself, and keeps no record of certificates already visited. The key-identifier links are followed without checking signatures.