Skip to content

CVE 2026 63572

Peter Dettman edited this page Oct 1, 2026 · 1 revision

CVE-2026-63572

Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.

Fixed versions: BC C# .NET 2.7.0

Platform affected: All CLRs.

When Pkcs12Store.Load opens a PKCS#12 (PFX) file, it derives keys from the password using iteration counts taken from the file itself: the count in the MacData for the integrity MAC, and the counts in the encryption parameters of each encrypted SafeContents and each PKCS#8 shrouded key bag. Nothing in the file is authenticated until the MAC has been computed, and a decryption cannot fail until its key has been derived. Earlier versions used the counts as given, up to 2^31 - 1. A zero or negative count, which made the PKCS#12 key derivation loop about 2^32 times, is covered separately by CVE-2026-63575. Pkcs12Utilities.ConvertToDefiniteLength(byte[], char[]), which recomputes the MAC, had the same problem.

Applications that load PKCS#12 files from an untrusted source are exposed, for example a service that accepts uploaded certificates and keys, or a tool that imports keystores received from others. The attacker does not need to know the password. On a current desktop CPU, a file of under 80 bytes with a crafted MAC iteration count keeps the loading thread busy for about a quarter of an hour, or twice as long if the password is empty, because the MAC is then computed a second time. A file without a MAC and with a crafted count on an encrypted bag takes 20 to 40 minutes. The caller cannot cancel the work, and repeated files can tie up every worker thread.

BC C# .NET 2.7.0 checks each iteration count before deriving a key from it. The MAC and contents encrypted with the PKCS#12 algorithms (such as pbeWithSHAAnd3-KeyTripleDES-CBC) are limited by the property "Org.BouncyCastle.Pkcs12.MaxIterationCount". Contents encrypted with PBES2 (PBKDF2) or PBES1 are limited by "Org.BouncyCastle.Pbe.MaxIterationCount", the limit that also applies to the private keys covered by CVE-2026-63578. Both default to 5,000,000 and can be set either as an environment variable or per thread through Org.BouncyCastle.Utilities.Properties. A count above the limit makes Load throw an InvalidOperationException (for the MAC and the PKCS#12 algorithms) or an ArgumentException (for PBES1 and PBES2), not an IOException, before any key derivation is done. Applications that deliberately create PKCS#12 files with more than 5,000,000 iterations need to raise the limits to read them.

Earlier versions have no setting that limits these counts, so upgrading is recommended. Where that is not immediately possible, applications can parse the file with Org.BouncyCastle.Asn1.Pkcs.Pfx before calling Load. They should reject it if the MacData iteration count, or the count in the parameters of any encrypted SafeContents, or of any shrouded key bag that is not itself inside encrypted contents, is below 1 or larger than they expect. Bags inside encrypted contents cannot be checked this way. Load only reaches them with the right password, so they matter only where whoever supplies the file also supplies its password.

The corresponding issue in BC Java was fixed in BC Java 1.85 (CVE-2026-13586).

Fix Commits:

Clone this wiki locally