Infinite Loop Vulnerability in Bouncy Castle for Java FIPS on Intel Platforms
CVE-2026-8798
Key Information:
- Status
- Vendor
- CVE Published:
- 8 August 2026
What is CVE-2026-8798?
A vulnerability exists in Bouncy Castle for Java FIPS prior to version 2.1.3, where the native entropy source on Intel platforms could enter an infinite retry loop. This occurs due to unbounded attempts to execute CPU entropy instructions (RDSEED and RDRAND) which may repeatedly fail without termination. As a result, any operation that relies on this native entropy source can hang indefinitely, leading to a denial of service for the application involved. The updated version adds bounds on these retry attempts and incorporates a mechanism to pause between retries, ensuring that the application does not become unresponsive under specific error conditions. The proper clearing of buffers on failure ensures that data integrity is maintained.
Affected Version(s)
BC-FJA x86 2.1.0 < 2.1.3
