Listen to this Post
The vulnerability is an Uncontrolled Resource Consumption issue within the native method bindings for cryptographic operations in Bouncy Castle’s Java FIPS and LTS providers. Specifically, the flaw exists in multiple native engine classes for AES (CFB, GCM, CBC, CTR, CCM, GCMSIV) and digest classes for SHA (224, 256, 384, 512, SHA3, SHAKE). When processing certain inputs, these components fail to impose adequate bounds on resource allocation. An attacker can exploit this by sending crafted data that triggers excessive memory allocation within the native code layer, bypassing the Java heap limits and directly consuming native system memory. This leads to a Denial-of-Service (DoS) condition by exhausting the available memory on the host system, rendering it unresponsive. The issue stems from a lack of proper input validation and constraints before passing data to the underlying native methods.
Platform: Bouncy Castle Java
Version: 2.1.0-2.1.1, 2.73.0-2.73.7
Vulnerability : Uncontrolled Resource Consumption
Severity: High
date: 2024-06-20
Prediction: 2024-07-15
What Undercode Say:
find . -name "AESNative.Java" -o -name "SHANativeDigest.Java"
// Example vulnerable call pattern AESNativeEngine engine = new AESNativeEngine(); engine.init(true, new KeyParameter(key)); engine.processBlock(input, 0, output, 0); // Potential excessive allocation point
How Exploit:
Craft malicious input data targeting native AES/SHA methods to trigger uncontrolled memory allocation, causing system-wide DoS.
Protection from this CVE
Upgrade to bc-fips version 2.1.2 or later, or bcprov-lts8on version 2.73.8 or later. Implement input size limits and monitor for anomalous memory consumption.
Impact:
Denial-of-Service (DoS) via system memory exhaustion, affecting application and host stability.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

