-
Notifications
You must be signed in to change notification settings - Fork 604
CVE 2026 103603
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
An HSS public key (RFC 8554) starts with its number of levels, L. RFC 8554 allows at most 8 levels, but BC C# .NET enforced this only when generating keys. HssPublicKeyParameters accepted any 32-bit value for L when decoding a key. When a signature was then verified under that key, HssSignature read the signature's count of signed public keys and checked only that it equalled L - 1. It then allocated an array of that many entries before reading the rest of the signature. Applications are exposed if they decode HSS public keys from untrusted sources and use them to verify signatures. Decoding happens through PqcPublicKeyFactory.CreateKey for an id-alg-hss-lms-hashsig SubjectPublicKeyInfo, or through HssPublicKeyParameters.GetInstance. Verification happens through HssSigner, HssPublicKeyParameters.GenerateLmsContext or HssSignature.GetInstance. The attacker has to supply both the public key and the signature, but neither needs to be valid. BC C# .NET does not use HSS/LMS in its own X.509 or CMS signature verification, so only applications that call these classes directly are affected.
A level count close to 2^31 makes a single verification allocate an array of up to about 17 GB in a 64-bit process, before the signature is rejected. Where that much memory is not available, an OutOfMemoryException is thrown instead, and in 2.6.2 it propagates out of HssSigner.VerifySignature. A few such requests can exhaust the memory of a server process and cause unrelated allocations in it to fail.
BC C# .NET 2.7.0 rejects an HSS public key whose level count is outside the range 1 to 8 (RFC 8554, Section 6) while the key is being decoded, so no such key reaches signature parsing. The limit is fixed and cannot be configured. The rejection is an InvalidDataException, which in .NET does not derive from IOException, so code that decodes untrusted keys should treat any exception from the decoder as an invalid key. 2.7.0 also rejects HSS and LMS public key encodings, and HSS signatures passed as byte arrays, that have extra data after their end.
Users of earlier versions who cannot upgrade immediately should check each decoded HssPublicKeyParameters before using it for verification. They should reject the key if its Level property (L in releases before 2.3.0) is less than 1 or greater than 8. Decoding the key does not allocate memory in proportion to the level count; only signature parsing does, so this check is enough.
The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-58060).
Fix Commits:
- https://github.com/bcgit/bc-csharp/commit/f47ad47c7b5745b53d3f9ac711a5a419a272a5d7 (limits the HSS level count to 1-8 and rejects trailing data)
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.