PT-2026-60591 · Legion Of The Bouncy Castle+2 · Bc-Lts+2
CVE-2026-15997
·
Published
2026-07-16
·
Updated
2026-07-17
CVSS v4.0
1.7
Low
| Vector | AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:P/AU:N/R:A/V:D/RE:M/U:Amber |
Name of the Vulnerable Software and Affected Versions
BC-LTS versions 2.73.0 through 2.73.12.0
Description
An out-of-bounds write issue in the bcprov-lts8on component on ARM architecture can lead to buffer overflows. This occurs when an application accepts memoable SHA3 or SHAKE states from potentially untrusted sources. The issue is linked to the
shake.C and sha3.C files.Recommendations
Update BC-LTS to version 2.73.12.1.
Avoid accepting memoable SHA3 or SHAKE states from untrusted sources as a mitigation measure.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bc-Lts
Bc-Lts-Java
Bouncy Castle