Bouncy Castle BC-LTS Out-of-Bounds Write Vulnerability on ARM Allowing Buffer Overflow

Vulnerability

A vulnerability allowing out-of-bounds write operations has been identified in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on, specifically on ARM architectures. This vulnerability, which affects versions 2.73.0 prior to 2.73.12.1, allows for buffer overflow conditions. The issue arises in the SHA3 and SHAKE implementations, when these memoable states are accepted from potentially untrusted sources.

Impact

Exploitation of this vulnerability can lead to buffer overflow conditions, which may be exploited to execute arbitrary code or cause a denial-of-service.

Added: Jul 17, 2026, 12:54 AM
Updated: Jul 17, 2026, 12:54 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.0
remediation
0.0
relevance
9.7
threat
0.0
urgency
5.7
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.