Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
History

Sun, 24 Aug 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Bouncycastle
Bouncycastle legion-of-the-bouncy-castle-fips-java-api
Vendors & Products Bouncycastle
Bouncycastle legion-of-the-bouncy-castle-fips-java-api

Fri, 22 Aug 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 09:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
Title native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/R:U/RE:M/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published: 2025-08-22T09:39:47.303Z

Updated: 2025-08-22T10:37:18.585Z

Reserved: 2025-08-22T08:45:05.505Z

Link: CVE-2025-9340

cve-icon Vulnrichment

Updated: 2025-08-22T10:37:10.871Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-22T10:15:33.050

Modified: 2025-08-22T18:08:51.663

Link: CVE-2025-9340

cve-icon Redhat

No data.