Skip to content

CVE 2026 103601

Peter Dettman edited this page Oct 1, 2026 · 1 revision

CVE-2026-103601

Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.

Fixed versions: BC C# .NET 2.7.0

Platform affected: All CLRs.

CcmBlockCipher (the NIST SP 800-38C CCM mode, also behind transformations such as "AES/CCM/NoPadding" from CipherUtilities) and KCcmBlockCipher (the DSTU 7624 CCM mode) process a whole message at once in DoFinal or ProcessPacket. When decrypting, they wrote the recovered plaintext straight into the caller's output buffer and only compared the authentication tag afterwards. If the tag was wrong, InvalidCipherTextException was thrown, but the buffer still held the unverified plaintext. An application is exposed if it decrypts untrusted messages into a buffer it supplies, using ProcessPacket with an output array or span, DoFinal(byte[], int), DoFinal(Span), or an IBufferedCipher DoFinal overload that takes an output array, and the contents of that buffer can reach an attacker after a failed decryption. That can happen, for example, through a pooled buffer reused without clearing, a log entry or an error response. Methods that return a newly allocated array do not expose the data, and neither does the TLS API.

Such an attacker can submit forged or altered ciphertexts and read their decryption even though the tag check fails. The affected mode then acts as an unauthenticated CTR decryption oracle, which can reveal the plaintext of captured messages. The key is not revealed, and forged messages are still rejected.

BC C# .NET 2.7.0 changes CcmBlockCipher to decrypt into a private buffer, check the tag, and copy the plaintext to the caller's buffer only if the tag is correct. The private buffer is cleared in either case, and after a failure the caller's buffer is left as it was. KCcmBlockCipher now clears the plaintext it has written to the caller's buffer before throwing InvalidCipherTextException. It also no longer writes the recovered MAC after the decrypted plaintext; the MAC is available from GetMac(). Results for valid ciphertexts are otherwise unchanged. The DSTU 7624 GCM mode (KGCM), which the BC Java issue also covers, is not part of BC C# .NET.

Users of earlier versions who cannot upgrade immediately should decrypt CCM and KCCM messages into a buffer used only for that operation. If InvalidCipherTextException is thrown, they should clear the buffer (for example with Array.Clear) before it is reused, logged or returned. For CcmBlockCipher, ProcessPacket(byte[], int, int) and the IBufferedCipher DoFinal overloads that return a new array also avoid the problem, since they return nothing when the tag check fails.

The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-58061).

Fix Commits:

Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.

Clone this wiki locally