{"id":"USN-8108-1","summary":"bouncycastle vulnerabilities","details":"It was discovered that Bouncy Castle did not sanitize user input when\ninserting it into an LDAP search filter. An attacker could possibly use\nthis issue to perform an LDAP injection attack. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2023-33201)\n\nIt was discovered that Bouncy Castle incorrectly handled specially crafted\nF2m parameters in the ECCurve algorithm. An attacker could possibly use\nthis issue to cause Bouncy Castle to use excessive resources, leading to a\ndenial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04\nLTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)\n\nIt was discovered that Bouncy Castle leaked timing information when\nhandling exceptions during an RSA handshake. An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.\n(CVE-2024-30171)\n\nIt was discovered that Bouncy Castle incorrectly handled endpoint\nidentification with an SSL socket enabled without an explicit hostname. An\nattacker could possibly use this issue to perform a DNS poisoning attack.\nThis issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu\n24.04 LTS. (CVE-2024-34447)\n\nBing Shi discovered that Bouncy Castle incorrectly handled resource memory\nallocation. An attacker could possibly use this issue to cause Bouncy\nCastle to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 24.04 LTS. (CVE-2025-8916)","modified":"2026-06-25T13:33:31.725378859Z","published":"2026-03-18T17:51:59Z","related":["UBUNTU-CVE-2023-33201","UBUNTU-CVE-2024-29857","UBUNTU-CVE-2024-30171","UBUNTU-CVE-2024-30172","UBUNTU-CVE-2024-34447","UBUNTU-CVE-2025-8916"],"upstream":["UBUNTU-CVE-2023-33201","UBUNTU-CVE-2024-29857","UBUNTU-CVE-2024-30171","UBUNTU-CVE-2024-30172","UBUNTU-CVE-2024-34447","UBUNTU-CVE-2025-8916"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8108-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-33201"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-29857"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-30171"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-30172"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-34447"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-8916"}],"affected":[{"package":{"name":"bouncycastle","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.51-4ubuntu1+esm1"}]}],"versions":["1.49+dfsg-3ubuntu1","1.51-4ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libbcmail-java","binary_version":"1.51-4ubuntu1+esm1"},{"binary_name":"libbcpg-java","binary_version":"1.51-4ubuntu1+esm1"},{"binary_name":"libbcpkix-java","binary_version":"1.51-4ubuntu1+esm1"},{"binary_name":"libbcprov-java","binary_version":"1.51-4ubuntu1+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8108-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"id":"CVE-2023-33201","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]}}},{"package":{"name":"bouncycastle","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.59-1ubuntu0.1~esm1"}]}],"versions":["1.57-1","1.58-1","1.59-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.59-1ubuntu0.1~esm1","binary_name":"libbcmail-java"},{"binary_name":"libbcpg-java","binary_version":"1.59-1ubuntu0.1~esm1"},{"binary_name":"libbcpkix-java","binary_version":"1.59-1ubuntu0.1~esm1"},{"binary_version":"1.59-1ubuntu0.1~esm1","binary_name":"libbcprov-java"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-33201"},{"id":"CVE-2024-29857","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-30171"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8108-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.61-1ubuntu0.1~esm1"}]}],"versions":["1.61-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libbcmail-java","binary_version":"1.61-1ubuntu0.1~esm1"},{"binary_version":"1.61-1ubuntu0.1~esm1","binary_name":"libbcpg-java"},{"binary_version":"1.61-1ubuntu0.1~esm1","binary_name":"libbcpkix-java"},{"binary_name":"libbcprov-java","binary_version":"1.61-1ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2023-33201","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2024-29857","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30171","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-34447","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8108-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.68-5ubuntu0.1~esm1"}]}],"versions":["1.68-2","1.68-4","1.68-5"],"ecosystem_specific":{"binaries":[{"binary_version":"1.68-5ubuntu0.1~esm1","binary_name":"libbcmail-java"},{"binary_version":"1.68-5ubuntu0.1~esm1","binary_name":"libbcpg-java"},{"binary_name":"libbcpkix-java","binary_version":"1.68-5ubuntu0.1~esm1"},{"binary_version":"1.68-5ubuntu0.1~esm1","binary_name":"libbcprov-java"},{"binary_name":"libbctls-java","binary_version":"1.68-5ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"id":"CVE-2023-33201","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-29857","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30171","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-34447","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8108-1.json"}},{"package":{"name":"bouncycastle","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.77-1ubuntu0.1~esm1"}]}],"versions":["1.72-2","1.77-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libbcjmail-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_name":"libbcmail-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_name":"libbcpg-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_name":"libbcpkix-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_name":"libbcprov-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_name":"libbctls-java","binary_version":"1.77-1ubuntu0.1~esm1"},{"binary_version":"1.77-1ubuntu0.1~esm1","binary_name":"libbcutil-java"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:24.04:LTS","cves":[{"id":"CVE-2024-29857","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-30171"},{"id":"CVE-2024-30172","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-34447","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2025-8916","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8108-1.json"}}],"schema_version":"1.7.5"}