Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes. | |
| Title | PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-10-02T07:06:31.876Z
Reserved: 2026-07-16T23:50:45.118Z
Link: CVE-2026-63575
No data.
Status : Received
Published: 2026-10-02T08:17:02.643
Modified: 2026-10-02T08:17:02.643
Link: CVE-2026-63575
No data.
OpenCVE Enrichment
Updated: 2026-10-02T09:15:08Z