-
Notifications
You must be signed in to change notification settings - Fork 604
CVE 2026 63569
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
DHAgreement implements MTI/A0 Diffie-Hellman, where each party combines a long-term (static) key pair with a fresh ephemeral one. Its CalculateAgreement method takes two values from the peer. The peer's static public key arrives as a DHPublicKeyParameters, which is validated. The peer's ephemeral value arrives as a plain BigInteger, which was not checked at all: it was raised to the local static private key without checking that it lies between 2 and p-2 or in the expected prime-order subgroup. Only applications that call DHAgreement directly are exposed. Bouncy Castle's own TLS and agreement factory code uses DHBasicAgreement, which is not affected.
An attacker who can replace the peer's ephemeral value in transit can pick one that forces the agreement to a fixed, known result. The party using DHAgreement then derives keys the attacker knows, while believing it is talking to the holder of the peer's static key. A malicious peer can instead send values of small order and, by watching how the resulting keys are used, learn the local static private key modulo small factors of p-1. With domain parameters where p-1 has many small factors, repeated exchanges recover the whole static key. With safe-prime groups, such as those in DHStandardGroups, this second attack reveals at most one bit, but the first still applies.
BC C# .NET 2.7.0 checks the ephemeral value the same way as a DH public key, by constructing a DHPublicKeyParameters from it with the agreement's domain parameters. Values outside 2 to p-2 are rejected. When the parameters include the subgroup order q, values outside that subgroup are rejected too. Either way CalculateAgreement throws an ArgumentException. The peer's static public key is also re-validated if it is passed as a subclass of DHPublicKeyParameters. There are no new settings. The subgroup check needs q, so DHParameters should include it, as the safe-prime groups in DHStandardGroups do.
Users of earlier versions can apply the same check themselves. Before calling CalculateAgreement, construct new DHPublicKeyParameters(message, dhParams) from the peer's ephemeral value, using the same parameters as the local key. Abandon the exchange if the constructor throws.
The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-59650).
Fix Commits:
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.