Skip to content

CVE 2026 63575

Peter Dettman edited this page Oct 1, 2026 · 1 revision

CVE-2026-63575

Issue affecting: BC C# .NET 2.6.2 and earlier, and the 2.7.0-beta.98 pre-release.

Fixed versions: BC C# .NET 2.7.0

Platform affected: All CLRs.

The PKCS#12 key derivation function (Pkcs12ParametersGenerator) repeats its hash as many times as the iteration count says. In earlier versions its loop ran until the counter was equal to the count, so a count of zero or a negative count was never reached: the counter wrapped around instead, giving about 2^32 iterations. The count comes from the data being processed, and nothing in that data can be checked until the key has been derived.

Applications are exposed if they load PKCS#12 (PFX) files from untrusted sources with Pkcs12Store.Load, which derives the integrity MAC key and the keys for contents encrypted with the PKCS#12 algorithms this way. They are also exposed if they decrypt PKCS#8 encrypted private keys that use a PKCS#12 password-based encryption algorithm, such as pbeWithSHAAnd3-KeyTripleDES-CBC, for example with PrivateKeyFactory.DecryptKey or PemReader. The attacker does not need to know the password. A 75-byte PFX file with a negative MacData iteration count keeps Load busy for many minutes on a current CPU. The caller cannot cancel the work, and a few such files can occupy every worker thread.

BC C# .NET 2.7.0 ends the derivation loop correctly for any count, so a count of zero or below no longer causes extra work. It also rejects a negative iteration count for the PKCS#12 MAC and the PKCS#12 algorithms with an InvalidOperationException, before any key derivation is done. Very large positive counts are covered by CVE-2026-63572 (PKCS#12 files) and CVE-2026-63578 (encrypted private keys).

Earlier versions have no setting that prevents this, so upgrading is recommended. Where that is not immediately possible, applications can parse the input themselves before passing it to Bouncy Castle and reject an iteration count below 1: for PKCS#12 files, the MacData count and the counts in the parameters of encrypted SafeContents and shrouded key bags (using Org.BouncyCastle.Asn1.Pkcs.Pfx); for PKCS#8 keys, the count in the EncryptedPrivateKeyInfo's algorithm parameters.

BC Java is not affected: its PKCS#12 key derivation loop ends correctly for any count.

Fix Commits:

Credit: Paweł Łukasik (https://github.com/pawlos)

Clone this wiki locally