Description
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.80.1, from 1.82 before 1.84.
Problem types
Product status
1.71 (maven) before 1.80.2
1.81 (maven) before 1.80.1
1.82 (maven) before 1.84
Credits
Cristina Dueñas Navarro (cristina.duenas@jtsec.es)
Sunwoo Lee and Seunghyun Yoon, Korea Institute of Energy Technology (KENTECH)
References
github.com/bcgit/bc-java/wiki/CVE‐2026‐5598
github.com/...ommit/94abbd56413dfdac651fd878bc60253871ef5e87
github.com/...ommit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5