critical Security update for bouncycastle
SUSE-SLE-Module-Development-Tools-15-SP7-2026-3559


This update for bouncycastle fixes the following issues: - CVE-2026-8763: Name Constraints bypass via trailing dot in rfc822Name and URI (bsc#1272700). - CVE-2026-12185: BKS/UBER keystore allocates from untrusted lengths before integrity check (bsc#1272701). - CVE-2026-12802: CMS AuthEnvelopedData fails to enforce tag-length on decryption (bsc#1272702). - CVE-2026-12803: KCCMBlockCipher MAC does not bind nonce when AAD is absent (bsc#1272703). - CVE-2026-12816: IESEngine stream-mode MAC forgery via length-dependent KDF split (bsc#1272704). - CVE-2026-12817: OpenPGP AEAD decryption skips final tag on chunk-aligned data (bsc#1272705). - CVE-2026-12852: MLS wire decoder allocates attacker-declared opaque length before bounds check (bsc#1272707). - CVE-2026-12860: RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (bsc#1272708). - CVE-2026-13506: Lazy ASN.1 sequence forcing resets nesting-depth guard (bsc#1272709). - CVE-2026-13586: PKCS#12 MAC and bag-decryption KDF iteration-count bound (bsc#1272710). - CVE-2026-14682: Possible OOM from unbounded up-front allocation on a definite-length read (bsc#1272711). - CVE-2026-15055: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (bsc#1272712). - CVE-2026-58059: Quadratic-time escaping when stringifying X.500 distinguished names (bsc#1272713). - CVE-2026-58060: HSS public-key level count unbounded, enabling huge allocation on verify (bsc#1272714). - CVE-2026-58061: CCM-family modes write plaintext to caller buffer before tag check (bsc#1272715). - CVE-2026-58062: Stapled OCSP response accepted without binding to the checked certificate (bsc#1272716). - CVE-2026-58063: BCFKS keystore load honours unbounded KDF cost from untrusted file (bsc#1272717). - CVE-2026-59638: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (bsc#1272718). - CVE-2026-59639: CMS verifySignatures returns true for SignedData with zero signers (bsc#1272719). - CVE-2026-59640: OpenPGP CFB quick-check oracle active on symmetric/session-key paths (bsc#1272720). - CVE-2026-59641: S/MIME validator trusts signer-asserted signingTime for path validation (bsc#1272721). - CVE-2026-59642: CMS AuthenticatedData content not bound to MAC when authAttrs present (bsc#1272722). - CVE-2026-59643: OpenPGP inline-signature policy failures silently ignored (bsc#1272723). - CVE-2026-59644: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (bsc#1272724). - CVE-2026-59645: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (bsc#1272725). - CVE-2026-59646: DTLS handshake reassembler allocates buffer from unchecked 24-bit length (bsc#1272726). - CVE-2026-59647: CRMF/CMP password-MAC honours unbounded iteration count (bsc#1272727). - CVE-2026-59648: OpenPGP Argon2 S2K honours attacker-chosen memory and passes (bsc#1272728). - CVE-2026-59649: OpenPGP user-attribute subpacket length bounded only by JVM max memory (bsc#1272729). - CVE-2026-59650: MTI/A0 DH agreement exponentiates unvalidated peer value (bsc#1272730). - CVE-2026-59651: BKS keystore accepts legacy version with 16-bit integrity MAC key (bsc#1272731). - CVE-2026-59652: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (bsc#1272732). Changes for bouncycastle: Update to 1.85: * Additional Notes: The standardised PQC algorithms ML-KEM, ML-DSA, SLH-DSA, FrodoKEM, and CMCE have been repackaged under org.bouncycastle.crypto and the versions under org.bouncycastle.crypto.pqc have been deprecated. These deprecated versions will be removed in BC 1.86.


cloud_download Downloads

Development Tools Module 15.7 aarch64
  • Packages
    bouncycastle
    Bouncy Castle Cryptography APIs for Java
    1.85-150200.3.38.1 lock rpm lock src
    bouncycastle-pg
    Bouncy Castle OpenPGP API
    1.85-150200.3.38.1 lock rpm
    bouncycastle-pkix
    Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs
    1.85-150200.3.38.1 lock rpm
    bouncycastle-util
    Bouncy Castle ASN.1 Extension and Utility APIs
    1.85-150200.3.38.1 lock rpm
Development Tools Module 15.7 ppc64le
  • Packages
    bouncycastle
    Bouncy Castle Cryptography APIs for Java
    1.85-150200.3.38.1 lock rpm lock src
    bouncycastle-pg
    Bouncy Castle OpenPGP API
    1.85-150200.3.38.1 lock rpm
    bouncycastle-pkix
    Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs
    1.85-150200.3.38.1 lock rpm
    bouncycastle-util
    Bouncy Castle ASN.1 Extension and Utility APIs
    1.85-150200.3.38.1 lock rpm
Development Tools Module 15.7 s390x
  • Packages
    bouncycastle
    Bouncy Castle Cryptography APIs for Java
    1.85-150200.3.38.1 lock rpm lock src
    bouncycastle-pg
    Bouncy Castle OpenPGP API
    1.85-150200.3.38.1 lock rpm
    bouncycastle-pkix
    Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs
    1.85-150200.3.38.1 lock rpm
    bouncycastle-util
    Bouncy Castle ASN.1 Extension and Utility APIs
    1.85-150200.3.38.1 lock rpm
Development Tools Module 15.7 x86_64
  • Packages
    bouncycastle
    Bouncy Castle Cryptography APIs for Java
    1.85-150200.3.38.1 lock rpm lock src
    bouncycastle-pg
    Bouncy Castle OpenPGP API
    1.85-150200.3.38.1 lock rpm
    bouncycastle-pkix
    Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs
    1.85-150200.3.38.1 lock rpm
    bouncycastle-util
    Bouncy Castle ASN.1 Extension and Utility APIs
    1.85-150200.3.38.1 lock rpm