天下漏洞,尽知其名
MEDIUM

CVE-2026-63574 Bouncy Castle bc-csharp 内存分配过大漏洞

影响远程未认证攻击者可触发内存耗尽导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Bouncy Castle bc-csharp 的 OpenPGP 签名子包与用户属性子包解析器在处理五字节长度形式的子包头时,未对声明长度设置上限,也未与所属子包区域或数据包大小进行比较。攻击者只需提供少量字节即可要求分配约 2 GB 的缓冲区,从而引发 OutOfMemoryException 或内存耗尽。

影响范围

Bouncy Castle bc-csharp

Legion of the Bouncy Castle Inc. bc-csharp 2.7.0 之前的版本。

漏洞详情

漏洞类型为不受控内存分配(内存分配过大)。成因是 SignatureSubpacketsParser.ReadPacket 与 UserAttributeSubpacketsParser.ReadPacket 在读取子包头时,直接使用声明的长度来分配子包缓冲区,既没有上限校验,也没有与外围子包区域或数据包的实际大小做比较。利用方式是构造带有五字节长度形式子包头的恶意 OpenPGP 公钥、证书或签名,在解析阶段即触发超大内存分配。

利用条件与风险

利用前提是目标应用使用受影响版本解析攻击者可控的 OpenPGP 公钥、证书或签名,且无需认证。实战中可造成解析进程内存耗尽或崩溃,形成拒绝服务。

修复建议

升级到 bc-csharp 2.7.0 或更高版本。临时缓解措施包括在解析前限制输入大小、对解析过程设置内存与超时限制,或避免解析不可信来源的 OpenPGP 数据。

原始情报

Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote, unauthenticated attacker who can supply a crafted OpenPGP public key, certificate or signature to cause a denial of service (OutOfMemoryException or memory exhaustion in the parsing process) via a subpacket header using the five-octet length form, because the declared length was used to size the subpacket buffer with no upper bound and without being compared with the size of the enclosing subpacket area or packet, so a few bytes of input could demand an allocation of up to about 2 GB before any subpacket data was read.