PT-2026-60591 · Legion Of The Bouncy Castle+2 · Bc-Lts+2

CVE-2026-15997

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v4.0

1.7

Low

VectorAV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:P/AU:N/R:A/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions BC-LTS versions 2.73.0 through 2.73.12.0
Description An out-of-bounds write issue in the bcprov-lts8on component on ARM architecture can lead to buffer overflows. This occurs when an application accepts memoable SHA3 or SHAKE states from potentially untrusted sources. The issue is linked to the shake.C and sha3.C files.
Recommendations Update BC-LTS to version 2.73.12.1. Avoid accepting memoable SHA3 or SHAKE states from untrusted sources as a mitigation measure.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15997

Affected Products

Bc-Lts
Bc-Lts-Java
Bouncy Castle