目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-17508— PBE 密钥派生函数参数未限制导致潜在漏洞

一分钟漏洞结论

影响对象
Legion of the Bouncy Castle Inc. BC-JAVA
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Bouncy Castle for Java 1.86 之前的版本中,多个基于密码的密钥派生函数(KDF)入口点使用了来自不受信任输入的成本参数来运行 KDF,且未对这些参数进行限制。因此,一个小的输入就可能强制执行任意量的计算工作,以至于在任何密码或完整性检查能够拒绝该输入之前,系统已经完成了大量工作。 受影响的入口包括: 1. RFC 9579 PBMAC1 MAC 计算器构建器:这些构建器直接从 中获取 PBKDF2 迭代计数和派生密钥长度,而未对这些值加以限制。具体涉及 和通过 调用的 。 2. PKC

CVSS 5.3 · Medium

可能的 ATT&CK 技术 1 AI

T1496 · Resource Hijacking
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-17508 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points
来源: CVE Program / CVE List V5
Vulnerability Description
In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key's own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.max_rounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber
来源: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Legion of the Bouncy Castle Inc. BC-JAVA 0 ~ 1.86 -
Legion of the Bouncy Castle Inc. BC-JAVA 0 ~ 1.86 -
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.0 ~ 2.73.13 -
Legion of the Bouncy Castle Inc. BC-LTS-JAVA 2.73.0 ~ 2.73.13 -
Legion of the Bouncy Castle Inc. BC-FJA 1.0.0 ~ 1.0.13 -

二、漏洞 CVE-2026-17508 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-17508 的情报信息

请登录查看更多情报信息。

CVE-2026-17508 其他参考 (7)

同批安全公告 · Legion of the Bouncy Castle Inc. · 2026-10-02 · 共 24 条

CVE-2026-63569 9.1 CRITICAL MTI/A0 DH协议未验证对端临时值
CVE-2026-63571 8.7 HIGH 属性证书路径验证未验证证书签名
CVE-2026-63566 8.7 HIGH DTLS握手重组器因未检查24位长度导致缓冲区分配漏洞
CVE-2026-63574 8.7 HIGH OpenPGP签名及用户属性子包长度未限制分配漏洞
CVE-2026-63568 8.7 HIGH CMP/CRMF密码MAC迭代计数无界导致CPU耗尽
CVE-2026-103600 8.7 HIGH ASN.1非受限嵌套深度导致进程终止的栈溢出
CVE-2026-103604 8.7 HIGH X.509 区分名转字符串时二次时间转义漏洞
CVE-2026-103603 8.7 HIGH HSS公钥无限制级数导致签名验证时数组分配过大漏洞
CVE-2026-16000 8.7 HIGH DSTU 7624 CCM 加密无关联数据时标签未绑定非
CVE-2026-17507 8.7 HIGH MLS 库整数类型转换漏洞,导致越界发送者
CVE-2026-103602 8.2 HIGH RFC822Name/URI hosts后缀点绕过Name Constraints限制漏洞
CVE-2026-18036 8.2 HIGH NTRU 非恒定时间整数除法泄露私钥
CVE-2026-63577 8.2 HIGH 目录名称约束绕过漏洞
CVE-2026-63576 8.2 HIGH URI名称约束对错误解析主机进行检查
CVE-2026-63573 8.2 HIGH CMS RSA PKCS#1 v1.5 填充 oracle 漏洞
CVE-2026-103601 8.2 HIGH CcmBlockCipher 和 KCcmBlockCipher 标签检查失败后未验证明文
CVE-2026-63567 8.2 HIGH IesEngine CBC模式填充预言漏洞
CVE-2026-15999 8.2 HIGH AES-CCM 解密漏洞:接受零值或越界标签长度导致认证绕过
CVE-2026-16001 8.2 HIGH IesEngine 流模式MAC伪造漏洞
CVE-2026-63578 7.1 HIGH Java 未限制 PBE 迭代次数导致 PKCS#8 私钥解密漏洞

显示前 20 条,共 24 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-17508

暂无评论


发表评论