-
Notifications
You must be signed in to change notification settings - Fork 604
CVE 2026 63570
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
Pkcs12Store.GetCertificateChain builds the certificate chain for a key entry one issuer at a time. It looks for each issuer among the certificates in the store, first by the key identifier in the AuthorityKeyIdentifier extension and otherwise by issuer name. The loop ended only when no issuer was found or a certificate pointed back to itself. It kept no record of the certificates it had already added, so if two or more certificates in a store named each other as issuer, the loop never ended.
Such a store is easy to produce, since issuers found through the key identifier are used without checking any signature. Pkcs12Store.Load accepts the file normally. The problem appears when the application then calls GetCertificateChain for the key entry, which is the usual next step. The call never returns. It keeps a CPU core busy and adds to the chain on every pass until memory runs out and an OutOfMemoryException is thrown, which can affect the whole process and not only the operation in progress. Applications are exposed if they load PKCS#12 files from untrusted sources, for example keystores uploaded by users for import, and request the certificate chain. Keystores that the application created itself or obtained from a trusted source are not a concern.
BC C# .NET 2.7.0 stops building the chain as soon as a certificate repeats and returns the certificates collected up to that point, each listed once. There is no new setting, and callers need no changes.
Earlier versions have no setting that prevents this, so upgrading is recommended for applications that handle PKCS#12 files from untrusted sources. Where that is not immediately possible, such applications should not call GetCertificateChain on those keystores; the key entry's own certificate is still available through GetCertificate.
Fix Commits:
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.