{"id":"SUSE-SU-2026:3559-1","summary":"Security update for bouncycastle","details":"This update for bouncycastle fixes the following issues:\n\n- CVE-2026-8763: Name Constraints bypass via trailing dot in rfc822Name and URI (bsc#1272700).\n- CVE-2026-12185: BKS/UBER keystore allocates from untrusted lengths before integrity check (bsc#1272701).\n- CVE-2026-12802: CMS AuthEnvelopedData fails to enforce tag-length on decryption (bsc#1272702).\n- CVE-2026-12803: KCCMBlockCipher MAC does not bind nonce when AAD is absent (bsc#1272703).\n- CVE-2026-12816: IESEngine stream-mode MAC forgery via length-dependent KDF split (bsc#1272704).\n- CVE-2026-12817: OpenPGP AEAD decryption skips final tag on chunk-aligned data (bsc#1272705).\n- CVE-2026-12852: MLS wire decoder allocates attacker-declared opaque length before bounds check (bsc#1272707).\n- CVE-2026-12860: RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (bsc#1272708).\n- CVE-2026-13506: Lazy ASN.1 sequence forcing resets nesting-depth guard (bsc#1272709).\n- CVE-2026-13586: PKCS#12 MAC and bag-decryption KDF iteration-count bound (bsc#1272710).\n- CVE-2026-14682: Possible OOM from unbounded up-front allocation on a definite-length read (bsc#1272711).\n- CVE-2026-15055: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (bsc#1272712).\n- CVE-2026-58059: Quadratic-time escaping when stringifying X.500 distinguished names (bsc#1272713).\n- CVE-2026-58060: HSS public-key level count unbounded, enabling huge allocation on verify (bsc#1272714).\n- CVE-2026-58061: CCM-family modes write plaintext to caller buffer before tag check (bsc#1272715).\n- CVE-2026-58062: Stapled OCSP response accepted without binding to the checked certificate (bsc#1272716).\n- CVE-2026-58063: BCFKS keystore load honours unbounded KDF cost from untrusted file (bsc#1272717).\n- CVE-2026-59638: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (bsc#1272718).\n- CVE-2026-59639: CMS verifySignatures returns true for SignedData with zero signers (bsc#1272719).\n- CVE-2026-59640: OpenPGP CFB quick-check oracle active on symmetric/session-key paths (bsc#1272720).\n- CVE-2026-59641: S/MIME validator trusts signer-asserted signingTime for path validation (bsc#1272721).\n- CVE-2026-59642: CMS AuthenticatedData content not bound to MAC when authAttrs present (bsc#1272722).\n- CVE-2026-59643: OpenPGP inline-signature policy failures silently ignored (bsc#1272723).\n- CVE-2026-59644: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (bsc#1272724).\n- CVE-2026-59645: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (bsc#1272725).\n- CVE-2026-59646: DTLS handshake reassembler allocates buffer from unchecked 24-bit length (bsc#1272726).\n- CVE-2026-59647: CRMF/CMP password-MAC honours unbounded iteration count (bsc#1272727).\n- CVE-2026-59648: OpenPGP Argon2 S2K honours attacker-chosen memory and passes (bsc#1272728).\n- CVE-2026-59649: OpenPGP user-attribute subpacket length bounded only by JVM max memory (bsc#1272729).\n- CVE-2026-59650: MTI/A0 DH agreement exponentiates unvalidated peer value (bsc#1272730).\n- CVE-2026-59651: BKS keystore accepts legacy version with 16-bit integrity MAC key (bsc#1272731).\n- CVE-2026-59652: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (bsc#1272732).\n\nChanges for bouncycastle:\n\nUpdate to 1.85:\n  \n  * Additional Notes:\n\n  The standardised PQC algorithms ML-KEM, ML-DSA, SLH-DSA, FrodoKEM, \n  and CMCE have been repackaged under org.bouncycastle.crypto and \n  the versions under org.bouncycastle.crypto.pqc have been deprecated. \n  These deprecated versions will be removed in BC 1.86.\n","modified":"2026-08-12T10:45:04.841132570Z","published":"2026-08-10T18:04:57Z","related":["CVE-2026-12185","CVE-2026-12802","CVE-2026-12803","CVE-2026-12816","CVE-2026-12817","CVE-2026-12852","CVE-2026-12860","CVE-2026-13506","CVE-2026-13586","CVE-2026-14682","CVE-2026-15055","CVE-2026-58059","CVE-2026-58060","CVE-2026-58061","CVE-2026-58062","CVE-2026-58063","CVE-2026-59638","CVE-2026-59639","CVE-2026-59640","CVE-2026-59641","CVE-2026-59642","CVE-2026-59643","CVE-2026-59644","CVE-2026-59645","CVE-2026-59646","CVE-2026-59647","CVE-2026-59648","CVE-2026-59649","CVE-2026-59650","CVE-2026-59651","CVE-2026-59652","CVE-2026-8763"],"upstream":["CVE-2026-12185","CVE-2026-12802","CVE-2026-12803","CVE-2026-12816","CVE-2026-12817","CVE-2026-12852","CVE-2026-12860","CVE-2026-13506","CVE-2026-13586","CVE-2026-14682","CVE-2026-15055","CVE-2026-58059","CVE-2026-58060","CVE-2026-58061","CVE-2026-58062","CVE-2026-58063","CVE-2026-59638","CVE-2026-59639","CVE-2026-59640","CVE-2026-59641","CVE-2026-59642","CVE-2026-59643","CVE-2026-59644","CVE-2026-59645","CVE-2026-59646","CVE-2026-59647","CVE-2026-59648","CVE-2026-59649","CVE-2026-59650","CVE-2026-59651","CVE-2026-59652","CVE-2026-8763"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263559-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272701"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272702"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272704"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272709"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272712"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272714"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272715"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272716"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272717"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272720"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272721"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272724"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272725"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272727"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272728"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272730"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272732"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12802"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14682"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58062"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59638"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59640"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59642"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59643"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59644"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59646"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59647"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59648"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59651"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8763"}],"affected":[{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle":"1.85-150200.3.38.1","bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.85-150200.3.38.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-pg":"1.85-150200.3.38.1","bouncycastle-pkix":"1.85-150200.3.38.1","bouncycastle-util":"1.85-150200.3.38.1","bouncycastle":"1.85-150200.3.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"}}],"schema_version":"1.9.0"}