Skip to content

CVE 2026 63568

Peter Dettman edited this page Oct 1, 2026 · 1 revision

CVE-2026-63568

Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.

Fixed versions: BC C# .NET 2.7.0

Platform affected: All CLRs.

PKMacBuilder implements the RFC 4211 password-based MAC (PBM) used to protect CMP messages and the PKMAC form of CRMF proof-of-possession. When it verifies a MAC, it takes the iteration count and hash algorithm from the PBMParameter carried in the message itself. The sender chooses these values, and nothing authenticates them until the key has been derived. PKMacBuilder only applied an upper limit to the iteration count if it had been constructed with PKMacBuilder(IPKMacPrimitivesProvider, int) and a positive maxIterations. The other constructors, including the default PKMacBuilder(), applied no limit.

An application that checks password-based MAC protection on input from untrusted parties is exposed. This covers ProtectedPkiMessage.Verify(PKMacBuilder, password) for CMP messages and CertificateRequestMessage.IsValidSigningKeyPop(..., PKMacBuilder, password) for CRMF requests. A single message can make it run up to about 2^31 hash iterations before the MAC is compared, and the sender needs no knowledge of the password. One such message can keep a CPU core busy for minutes, so a handful of them can exhaust a CMP server such as a CA or RA. Applications that only create PBM-protected messages, or that verify messages only from trusted sources, are not affected.

BC C# .NET 2.7.0 limits the iteration count to 1,000,000 by default whenever no positive maxIterations was given to the PKMacBuilder(IPKMacPrimitivesProvider, int) constructor. An explicit maxIterations still takes precedence. Counts below 1 or outside the Int32 range are also rejected. A rejected count causes an ArgumentException before any hashing is done, and callers should treat it as a failed verification. The default can be adjusted with the property "Org.BouncyCastle.PKMac.MaxIterationCount", set either as an environment variable or per thread through Org.BouncyCastle.Utilities.Properties.

Users of earlier versions who cannot upgrade immediately can construct the PKMacBuilder they use for verification as new PKMacBuilder(new DefaultPKMacPrimitivesProvider(), maxIterations), with a positive maxIterations that covers the counts their legitimate peers use. That constructor is available in all 2.x releases and is intended for verification only. Alternatively, they can read the iteration count from the message's protection algorithm parameters and reject excessive values before calling Verify or IsValidSigningKeyPop.

The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-59647).

Fix Commits:

Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.

Clone this wiki locally