CVE-2025-8885

NameCVE-2025-8885
DescriptionAllocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcprov, bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/core/src/main/java/org/bouncycastle/asn1/ASN1ObjectIdentifier.Java. This issue affects Bouncy Castle for Java: from BC 1.0 through 1.77, from BC-FJA 1.0.0 through 1.0.2.5, from BC-FJA 2.0.0 through 2.0.0.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bouncycastle (PTS)bullseye1.68-2vulnerable
bookworm1.72-2vulnerable
forky, sid, trixie1.80-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bouncycastlesource(unstable)1.80-1

Notes

[bookworm] - bouncycastle <no-dsa> (Minor issue)
[bullseye] - bouncycastle <postponed> (minor vulnerability; DoS)
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%908885
Fixed by: https://github.com/bcgit/bc-java/commit/3790993df5d28f661a64439a8664343437ed3865 (r1rv78v1)

Search for package or bug name: Reporting problems