{"id":"SUSE-SU-2026:1639-1","summary":"Security update for bouncycastle","details":"This update for bouncycastle fixes the following issues:\n\nUpdate to version 1.84.\n\nSecurity issues fixed:\n\n- CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225).\n- CVE-2026-0636: LDAP injection in LDAPStoreHelper.java leads to information disclosure (bsc#1262226).\n- CVE-2026-3505: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232).\n- CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228).\n- CVE-2026-5598: non-constant time comparisons risks private key leakage in FrodoKEM (bsc#1262227).\n\nOther updates and bugfixes:\n\n- Version 1.84:\n  - In line with JVM changes, KEM support has been backported to\n    Java 17.\n  - BCJSSE: Configurable (client) early key_share groups via\n    BCSSLParameters.earlyKeyShares or\n    'org.bouncycastle.jsse.client.earlyKeyShares' system property.\n  - BCJSSE: Support for curveSM2MLKEM768 hybrid NamedGroup in TLS\n    1.3 per draft-yang-tls-hybrid-sm2-mlkem-03.\n  - BCJSSE: Log when default cipher suites are disabled.\n  - BCJSSE: Experimental support for ShangMi crypto in TLS 1.3 per\n    RFC 8998 (not enabled by default).\n  - CMS: Added CMSAuthEnvelopedDataStreamGenerator.open taking an\n    explicit content type.\n  - HKDF: Provider support for HKDFParameterSpec.Expand.\n  - Added initial support for RFC 9380 (Hashing to Elliptic Curves);\n    see org.bouncycastle.crypto.hash2curve .\n  - PKCS12: Added default max iteration count of 5,000,000 (configurable\n    via 'org.bouncycastle.pkcs12.max_it_count' property).\n  - TLS: Use javax.crypto.KEM API (when available) to access ML-KEM\n    implementation (incl. hybrids).\n  - A new KeyStore, PKCS12-PBMAC1, has been added which defaults to\n    using PBMAC1 and supports RFC 9879.\n  - A new property 'org.bouncycastle.asn1.max_cons_depth' has been added\n    to allow setting of the maximum nesting for SETs/SEQUENCESs in ASN.1.\n    Default is 32.\n  - A new property 'org.bouncycastle.asn1.max_limit' has been added\n    to allow setting of the stream size of ASN.1 encodings. The value can\n    be either in bytes, or appended with k (1 kilobyte blocks), m (1\n    megabyte blocks), or g (1 gigabyte blocks).\n  - Added NTRU+ support to the lightweight PQC API and the BCPQC provider.\n  - Added SM4 key wrap/unwrap mode, SM2 key exchange, and logging to SM2Signer.\n  - OpenPGP: Added encryption-key filtering by purpose, a new OpenPGPKey\n    constructor, KeyPassphraseProvider-based passphrase change, wildcard\n    (anonymous) recipient handling, and Web-of-Trust methods for\n    third-party signature chains and delegations.\n  - CMSSignedDataStreamGenerator can now support the generation of DER/DL\n    encoded SignedData objects (note memory restrictions still apply).\n  - It is now possible to add extra digest alorithm IDs to\n    CMSSignedDataStreamGenerator when required.\n  - Random numbers being generated for DSTU4145 signature calculations\n    were 1 bit shorter than they could be. The code has been corrected\n    to allow the generated numbers to occupy the full numeric range available.\n  - HKDF implementation has been corrected to use multiple IKMs if available.\n  - CompositePublic/PrivateKey builders had an issue identifying brainpool\n    and EdDSA curves from the algorithm names due to an error in the OID\n    mapping table. This has been fixed.\n  - S/MIME: Fix AuthEnveloped support for AES192/GCM and AES256/GCM.\n  - CMS: Use implicit tag for AuthEnvelopedData.authEncryptedContentInfo.encryptedContent.\n  - Fixed Strings.split to handle delimiters at position 0.\n  - Fixed FrodoKEM error sampling to be constant-time.\n  - Fixed PKIXNameConstraintValidator to treat a DNS name as intersecting itself.\n  - Fixed PKCS12 key stores not calling getInstance with the original provider\n    (which was forcing provider registration).\n  - A resource leak due to the SMIMESigned constructor leaving background\n    threads hanging on MessagingException has been fixed.\n  - OpenPGP: Fixed an issue where a custom signature creation time was\n    ignored when generating message signatures.\n  - OpenPGP: Fixed SKESK encoding for direct-S2K-encrypted messages.\n\n- Version 1.83:\n  - Attempting to check a password on a stripped PGP would throw an\n    exception. Checking the password on such a key will now always\n    return false.\n  - Fixed an issue in KangarooTwelve where premature absorption caused\n    erroneous 168-byte padding; absorption is now delayed so correct\n    final-byte padding is applied.\n  - BCJSSE: Fix supported_versions creation for renegotiation handshake.\n  - (D)TLS: Reneg info now oly offered with pre-1.3.\n  - A generic 'COMPOSITE' algorithm name has been added as a JCA\n    Signature algorithm. The algorithm will identify the composite\n    signature to use from the composite key passed in.\n  - The composite signatures implementation has been updated to the\n    final draft and now follows the submitted standard.\n  - Support for the generation and use as trust anchors has been added\n    for certificate signatures with id-alg-unsigned as the signature type.\n  - Support for CMP direct POP for encryption keys using\n    challenge/response has been added to the CMP/CRMF APIs.\n  - Support for SupportedCurves attribute to the BC provider\n  - BCJSSE: Added support for SLH-DSA signature schemes in TLS 1.3 per\n    draft-reddy-tls-slhdsa-01.\n  - Support has been added for the Java 25 KDF API (current algorithms,\n    PBKDF2, SCRYPT, and HKDF).\n  - Support for composite signatures is now included in CMS and timestamping.\n  - It is now possible to disable the Lenstra check in RSA where the public\n    key is not available via the system/security property\n    'org.bouncycastle.rsa.no_lenstra_check'.\n\n- Version 1.82:\n  - SNOVA and MAYO are now correctly added to the JCA provider module-info file.\n  - TLS: Avoid nonce reuse error in JCE AEAD workaround for pre-Java7.\n  - BCJSSE: Session binding map is now shared across all stages of the\n    session lifecycle (SunJSSE compatibility).\n  - The CMCEPrivateKeyParameters#reconstructPublicKey method was returning\n    an empty byte array. It now returns an encoding of the public key.\n  - CBZip2InputStream no longer auto-closes at end-of-contents.\n  - The BC CertPath implementation was eliminating certificates on the\n    bases of the Key-ID. This is not in accordance with RFC 4158.\n  - Support for the previous set of libOQS Falcon OIDs has been restored.\n  - The BC CipherInputStream could throw an exception if asked to handle an\n    AEAD stream consisting of the MAC only.\n  - Some KeyAgreement classes were missing in the Java 11 class hierarchy.\n  - Fix typo in a constant name in the HPKE class and deprecate the old constant.\n  - Fuzzing analysis has been done on the OpenPGP API and additional code\n    has been added to prevent escaping exceptions.\n  - SHA3Digest, CSHAKE, TupleHash, KMAC now provide support for Memoable\n    and EncodableService.\n  - BCJSSE: Added support for integrity-only cipher suites in TLS 1.3 per RFC 9150.\n  - BCJSSE: Added support for system properties 'jdk.tls.{client,server}.maxInboundCertificateChainLength'\n  - BCJSSE: Added support for ML-DSA signature schemes in TLS 1.3 per draft-ietf-tls-mldsa-00.\n  - The Composite post-quantum signatures implementation has been updated to\n    the latest draft (07) draft-ietf-lamps-pq-composite-sigs.\n  - '_PREHASH' implementations are now provided for all composite signatures\n    to allow the hash of the date to be used instead of the actual data in\n    signature calculation.\n  - The gradle build can now be used to generate an Bill of Materials (BOM) file.\n  - It is now possible to configure the SignerInfoVerifierBuilder used by the\n    SignedMailValidator class.\n  - The Ascon family of algorithms has been updated with the latest published changes.\n  - Composite signature keys can now be constructed from the individual keys of\n    the algorithms composing the composite.\n  - PGPSecretKey, PGPSignatureGenerator now support version 6.\n  - Further optimisation work has been done on ML-KEM public key validation.\n  - Zeroization of passwords in the JCA PKCS12 key store has been improved.\n  - The 'org.bouncycastle.drbg.effective_256bits_entropy' property has been\n    added for platforms where the entropy source is not producing 1 full bit\n    of entropy per bit and additional bits are required (default value 282).\n  - OpenPGPKeyGenerator now allows for the use of empty UserIDs (version 4 compatibility).\n  - The HQC KEM has been updated with the latest draft updates.\n  - The legacy post-quantum package has now been removed.\n\n- Version 1.81:\n  - A potention NullPointerException in the KEM KDF KemUtil class\n    has been removed.\n  - Overlapping input/output buffers in doFinal could result in\n    data corruption.\n  - Fixed Grain-128AEAD decryption incorrectly handle MAC verification.\n  - Add configurable header validation to prevent malicious header\n    injection in PGP cleartext signed messages; Fix signature packet\n    encoding issues in PGPSignature.join() and embedded signatures\n    while phasing out legacy format.\n  - Fixed ParallelHash initialization stall when using block size B=0.\n  - The PRF from the PBKDF2 function was been lost when PBMAC1 was\n    initialized from protectionAlgorithm. This has been fixed.\n  - The lowlevel DigestFactory was cloning MD5 when being asked\n    to clone SHA1.\n  - XWing implementation updated to draft-connolly-cfrg-xwing-kem/07/\n  - Further support has been added for generation and use of PGP V6 keys\n  - Additional validation has been added for armored headers in Cleartext\n    Signed Messages.\n  - The PQC signature algorithm proposal Mayo has been added to the\n    low-level API and the BCPQC provider.\n  - The PQC signature algorithm proposal Snova has been added to the\n    low-level API and the BCPQC provider.\n  - Support for ChaCha20-Poly1305 has been added to the CMS/SMIME APIs.\n  - The Falcon implementation has been updated to the latest draft.\n  - Support has been added for generating keys which encode as seed-only\n    and expanded-key-only for ML-KEM and ML-DSA private keys.\n  - Private key encoding of ML-DSA and ML-KEM private keys now follows\n    the latest IETF draft.\n  - The Ascon family of algorithms has been updated to the initial draft\n    of SP 800-232. Some additional optimisation work has been done.\n  - Support for ML-DSA's external-mu calculation and signing has been\n    added to the BC provider.\n  - CMS now supports ML-DSA for SignedData generation.\n  - Introduce high-level OpenPGP API for message creation/consumption\n    and certificate evaluation.\n  - Added JDK21 KEM API implementation for HQC algorithm.\n  - BCJSSE: Strip trailing dot from hostname for SNI, endpointID checks.\n  - BCJSSE: Draft support for ML-KEM updated (draft-connolly-tls-mlkem-key-agreement-05).\n  - BCJSSE: Draft support for hybrid ECDHE-MLKEM (draft-ietf-tls-ecdhe-mlkem-00).\n  - BCJSSE: Optionally prefer TLS 1.3 server's supported_groups order\n    (BCSSLParameters.useNamedGroupsOrder).\n\n- Version 1.80:\n  - A splitting issue for ML-KEM led to an incorrect size for kemct\n    in KEMRecipientInfos. This has been fixed.\n  - The PKCS12 KeyStore has been adjusted to prevent accidental doubling\n    of the Oracle trusted certificate attribute (results in an IOException\n    when used with the JVM PKCS12 implementation).\n  - The SignerInfoGenerator copy constructor was ignoring the certHolder field.\n  - The getAlgorithm() method return value for a CompositePrivateKey was\n    not consistent with the corresponding getAlgorithm() return value for\n    the CompositePrivateKey. This has been fixed.\n  - The international property files were missing from the bcjmail distribution.\n  - Issues with ElephantEngine failing on processing large/multi-block messages\n    have been addressed.\n  - GCFB mode now fully resets on a reset.\n  - The lightweight algorithm contestants: Elephant, ISAP, PhotonBeetle,\n    Xoodyak now support the use of the AEADParameters class and provide\n    accurate update/doFinal output lengths.\n  - An unnecessary downcast in CertPathValidatorUtilities was resulting\n    in the ignoring of URLs for FTP based CRLs.\n  - A regression in the OpenPGP API could cause NoSuchAlgorithmException\n    to be thrown when attempting to use SHA-256 in some contexts.\n  - EtsiTs1029411TypesAuthorization was missing an extension field.\n  - Interoperability issues with single depth LMS keys have been addressed.\n  - CompositeSignatures now updated to draft-ietf-lamps-pq-composite-sigs-03.\n  - ML-KEM, ML-DSA, SLH-DSA, and Composite private keys now use raw encodings\n    as per the latest drafts from IETF 121: draft-ietf-lamps-kyber-certificates-06,\n    draft-ietf-lamps-dilithium-certificates-05, and draft-ietf-lamps-x509-slhdsa.\n  - Initial support has been added for RFC 9579 PBMAC1 in the PKCS API.\n  - Support has been added for EC-JPAKE to the lightweight API.\n  - Support has been added for the direct construction of S/MIME AuthEnvelopedData\n    objects, via the SMIMEAuthEnvelopedData class.\n  - An override 'org.bouncycastle.asn1.allow_wrong_oid_enc' property has been\n    added to disable new OID encoding checks (use with caution).\n  - Support has been added for the PBEParemeterSpec.getParameterSpec()\n    method where supported by the JVM.\n  - ML-DSA/SLH-DSA now return null for Signature.getParameters() if no context\n    is provided. This allows the algorithms to be used with the existing Java key tool.\n  - HQC has been updated to reflect the reference implementation released on 2024-10-30.\n  - Support has been added to the low-level APIs for the OASIS Shamir Secret\n    Splitting algorithms.\n  - BCJSSE: System property 'org.bouncycastle.jsse.fips.allowGCMCiphersIn12'\n    no longer used. FIPS TLS 1.2 GCM suites can now be enabled according to\n    JcaTlsCrypto#getFipsGCMNonceGeneratorFactory (see JavaDoc for details) if\n    done in alignment with FIPS requirements.\n  - Support has been added for OpenPGP V6 PKESK and message encryption.\n  - PGPSecretKey.copyWithNewPassword() now includes AEAD support.\n  - The ASCON family of algorithms have been updated in accordance with the\n    published FIPS SP 800-232 draft.\n","modified":"2026-04-29T08:00:48.779038Z","published":"2026-04-28T11:10:37Z","related":["CVE-2025-14813","CVE-2026-0636","CVE-2026-3505","CVE-2026-5588","CVE-2026-5598"],"upstream":["CVE-2025-14813","CVE-2026-0636","CVE-2026-3505","CVE-2026-5588","CVE-2026-5598"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261639-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262225"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262232"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3505"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5598"}],"schema_version":"1.7.5"}