-
Notifications
You must be signed in to change notification settings - Fork 603
CVE 2026 15999
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
AES-CCM decryption did not check the length of the authentication tag it was asked to verify. CcmParameters, which reads the RFC 5084 CCMParameters (nonce and aes-ICVlen) from an AlgorithmIdentifier, accepted any tag length, and CcmBlockCipher only enforced the permitted tag lengths when initialised for encryption. With a declared tag length of zero the tag comparison covers no bytes and always succeeds. Very short or odd lengths (for example one octet) leave a tag that can simply be guessed.
Applications are exposed when the tag length used for decryption comes from data an attacker can modify. This applies to ParameterUtilities.GetCipherParameters with an id-aes128-CCM, id-aes192-CCM or id-aes256-CCM AlgorithmIdentifier (from 2.1.0), and through it to CmsEnvelopedData and CmsEnvelopedDataParser when an EnvelopedData message uses AES-CCM for content encryption. It also applies to any code that passes an unchecked tag length to CcmBlockCipher for decryption. Someone able to alter such a message in transit can remove its authentication and change the encrypted content, and the altered plaintext is returned as if it had been verified. Confidentiality is not affected. BC C# .NET does not support decryption of CMS AuthEnvelopedData, so that content type is not affected.
BC C# .NET 2.7.0 restricts CcmParameters to the tag lengths RFC 5084 allows (4, 6, 8, 10, 12, 14 or 16 octets, defaulting to 12), both when parsing and in the public constructor. CcmBlockCipher now applies the same restriction when initialised for decryption. Other values are rejected with an ArgumentException. GcmParameters is likewise restricted to the RFC 5084 range of 12 to 16 octets. AES-GCM was not open to a zero-length tag, but it previously accepted tags as short as 4 octets when they were declared in the parameters.
Earlier versions have no setting that prevents this, so upgrading is recommended. Where that is not immediately possible, applications that decrypt AES-CCM using parameters taken from a message should check the tag length before decrypting. For CMS, inspect CmsEnvelopedData.EncryptionAlgorithmID (or the same property on CmsEnvelopedDataParser); for other code, check CcmParameters.IcvLen or the MacSize of the AeadParameters passed to CcmBlockCipher. Reject anything other than the tag length the application expects, or at the very least anything outside 4 to 16 octets in steps of 2.
A related issue in BC Java, concerning the tag length accepted when decrypting CMS AuthEnvelopedData, was fixed in BC Java 1.85 (CVE-2026-12802).
Fix Commits:
- https://github.com/bcgit/bc-csharp/commit/2818bdfa55efd58b0d6a1c75f360b8404d879780 (validates the ICV length in CcmParameters and GcmParameters)
- https://github.com/bcgit/bc-csharp/commit/9d284d8f379614def853b590c62bbb31c48f7af0 (checks the CCM tag length on decryption)
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.