{"id":"openSUSE-SU-2026:20627-1","summary":"Security update for bouncycastle","details":"This update for bouncycastle fixes the following issues:\n\n- Update to version 1.84:\n- CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225).\n- CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java (bsc#1262226).\n- CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232).\n- CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228).\n- CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM (bsc#1262227).\n","modified":"2026-04-29T18:24:02.649930Z","published":"2026-04-24T15:26:29Z","related":["CVE-2025-14813","CVE-2026-0636","CVE-2026-3505","CVE-2026-5588","CVE-2026-5598"],"upstream":["CVE-2025-14813","CVE-2026-0636","CVE-2026-3505","CVE-2026-5588","CVE-2026-5598"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262225"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262232"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3505"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5598"}],"schema_version":"1.7.5"}