-
Notifications
You must be signed in to change notification settings - Fork 604
CVE 2026 63574
Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.
Fixed versions: BC C# .NET 2.7.0
Platform affected: All CLRs.
The OpenPGP parsers for signature subpackets and user attribute subpackets (SignatureSubpacketsParser and UserAttributeSubpacketsParser) created the buffer for each subpacket body directly from the length in the subpacket header. The five-octet form of that header can declare a length of several gigabytes, and no upper limit was applied. The declared length was also not compared with the amount of data actually present in the enclosing signature subpacket area or user attribute packet, so a subpacket header of a few bytes could demand an array of up to about 2 GB before any of its body had been read.
Any application that parses OpenPGP data from an untrusted source is exposed: public keys and key rings (for example fetched from a keyserver or received as an attachment), detached and inline signatures, certifications, and messages read through PgpObjectFactory. Subpackets are parsed as the packet is read, before any signature is verified, so the attacker needs no key and no trust relationship. Each such input either fails with an OutOfMemoryException, which is not an IOException and so is not caught by handlers written for malformed input, or causes a temporary allocation of up to about 2 GB; repeated or concurrent inputs can exhaust the memory available to the process.
BC C# .NET 2.7.0 rejects any signature or user attribute subpacket whose declared length exceeds 2 MiB, the value of the read-only fields SignatureSubpacketsParser.MaxSubpacketLength and UserAttributeSubpacketsParser.MaxSubpacketLength. A signature subpacket longer than 2 KB that claims more data than remains in its subpacket area is also rejected. Such input fails with a MalformedPacketException, which is an IOException, before the buffer is allocated, so callers that already handle malformed input need no changes.
Earlier versions have no setting that prevents this, so upgrading is recommended. Limiting the size of the input does not help, since the trigger is a header of a few bytes. Where an upgrade is not immediately possible, applications should treat an OutOfMemoryException raised while parsing untrusted OpenPGP data as a parse failure, and limit how many such parses can run at the same time.
The corresponding issue in BC Java, for user attribute subpackets, was fixed in BC Java 1.85 (CVE-2026-59649).
Fix Commits:
- https://github.com/bcgit/bc-csharp/commit/f51dacf4817d9ea10d0a9841f72fac3655c65483 (adds the 2 MiB limit)
- https://github.com/bcgit/bc-csharp/commit/986fb4892bb39f292ba0fd82eba11d2cbc503217 (adds the check against the remaining data and MalformedPacketException)
Credit: Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.