Infinite Loop Vulnerability in Bouncy Castle for Java FIPS on Intel Platforms
CVE-2026-8798

8.7HIGH

What is CVE-2026-8798?

A vulnerability exists in Bouncy Castle for Java FIPS prior to version 2.1.3, where the native entropy source on Intel platforms could enter an infinite retry loop. This occurs due to unbounded attempts to execute CPU entropy instructions (RDSEED and RDRAND) which may repeatedly fail without termination. As a result, any operation that relies on this native entropy source can hang indefinitely, leading to a denial of service for the application involved. The updated version adds bounds on these retry attempts and incorporates a mechanism to pause between retries, ensuring that the application does not become unresponsive under specific error conditions. The proper clearing of buffers on failure ensures that data integrity is maintained.

Affected Version(s)

BC-FJA x86 2.1.0 < 2.1.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.