Bouncy Castle Java, Uncontrolled Resource Consumption, CVE-2024-30171 (High)

Listen to this Post

The vulnerability is an Uncontrolled Resource Consumption issue within the native method bindings for cryptographic operations in Bouncy Castle’s Java FIPS and LTS providers. Specifically, the flaw exists in multiple native engine classes for AES (CFB, GCM, CBC, CTR, CCM, GCMSIV) and digest classes for SHA (224, 256, 384, 512, SHA3, SHAKE). When processing certain inputs, these components fail to impose adequate bounds on resource allocation. An attacker can exploit this by sending crafted data that triggers excessive memory allocation within the native code layer, bypassing the Java heap limits and directly consuming native system memory. This leads to a Denial-of-Service (DoS) condition by exhausting the available memory on the host system, rendering it unresponsive. The issue stems from a lack of proper input validation and constraints before passing data to the underlying native methods.
Platform: Bouncy Castle Java
Version: 2.1.0-2.1.1, 2.73.0-2.73.7
Vulnerability : Uncontrolled Resource Consumption
Severity: High
date: 2024-06-20

Prediction: 2024-07-15

What Undercode Say:

find . -name "AESNative.Java" -o -name "SHANativeDigest.Java"
// Example vulnerable call pattern
AESNativeEngine engine = new AESNativeEngine();
engine.init(true, new KeyParameter(key));
engine.processBlock(input, 0, output, 0); // Potential excessive allocation point

How Exploit:

Craft malicious input data targeting native AES/SHA methods to trigger uncontrolled memory allocation, causing system-wide DoS.

Protection from this CVE

Upgrade to bc-fips version 2.1.2 or later, or bcprov-lts8on version 2.73.8 or later. Implement input size limits and monitor for anomalous memory consumption.

Impact:

Denial-of-Service (DoS) via system memory exhaustion, affecting application and host stability.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top