SUSE-SU-2026:3559-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263559-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3559-1
Upstream
CVE (32)
Related
Published
2026-08-10T18:04:57Z
Modified
2026-08-12T10:45:04Z
Summary
Security update for bouncycastle
Details

This update for bouncycastle fixes the following issues:

  • CVE-2026-8763: Name Constraints bypass via trailing dot in rfc822Name and URI (bsc#1272700).
  • CVE-2026-12185: BKS/UBER keystore allocates from untrusted lengths before integrity check (bsc#1272701).
  • CVE-2026-12802: CMS AuthEnvelopedData fails to enforce tag-length on decryption (bsc#1272702).
  • CVE-2026-12803: KCCMBlockCipher MAC does not bind nonce when AAD is absent (bsc#1272703).
  • CVE-2026-12816: IESEngine stream-mode MAC forgery via length-dependent KDF split (bsc#1272704).
  • CVE-2026-12817: OpenPGP AEAD decryption skips final tag on chunk-aligned data (bsc#1272705).
  • CVE-2026-12852: MLS wire decoder allocates attacker-declared opaque length before bounds check (bsc#1272707).
  • CVE-2026-12860: RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (bsc#1272708).
  • CVE-2026-13506: Lazy ASN.1 sequence forcing resets nesting-depth guard (bsc#1272709).
  • CVE-2026-13586: PKCS#12 MAC and bag-decryption KDF iteration-count bound (bsc#1272710).
  • CVE-2026-14682: Possible OOM from unbounded up-front allocation on a definite-length read (bsc#1272711).
  • CVE-2026-15055: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (bsc#1272712).
  • CVE-2026-58059: Quadratic-time escaping when stringifying X.500 distinguished names (bsc#1272713).
  • CVE-2026-58060: HSS public-key level count unbounded, enabling huge allocation on verify (bsc#1272714).
  • CVE-2026-58061: CCM-family modes write plaintext to caller buffer before tag check (bsc#1272715).
  • CVE-2026-58062: Stapled OCSP response accepted without binding to the checked certificate (bsc#1272716).
  • CVE-2026-58063: BCFKS keystore load honours unbounded KDF cost from untrusted file (bsc#1272717).
  • CVE-2026-59638: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (bsc#1272718).
  • CVE-2026-59639: CMS verifySignatures returns true for SignedData with zero signers (bsc#1272719).
  • CVE-2026-59640: OpenPGP CFB quick-check oracle active on symmetric/session-key paths (bsc#1272720).
  • CVE-2026-59641: S/MIME validator trusts signer-asserted signingTime for path validation (bsc#1272721).
  • CVE-2026-59642: CMS AuthenticatedData content not bound to MAC when authAttrs present (bsc#1272722).
  • CVE-2026-59643: OpenPGP inline-signature policy failures silently ignored (bsc#1272723).
  • CVE-2026-59644: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (bsc#1272724).
  • CVE-2026-59645: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (bsc#1272725).
  • CVE-2026-59646: DTLS handshake reassembler allocates buffer from unchecked 24-bit length (bsc#1272726).
  • CVE-2026-59647: CRMF/CMP password-MAC honours unbounded iteration count (bsc#1272727).
  • CVE-2026-59648: OpenPGP Argon2 S2K honours attacker-chosen memory and passes (bsc#1272728).
  • CVE-2026-59649: OpenPGP user-attribute subpacket length bounded only by JVM max memory (bsc#1272729).
  • CVE-2026-59650: MTI/A0 DH agreement exponentiates unvalidated peer value (bsc#1272730).
  • CVE-2026-59651: BKS keystore accepts legacy version with 16-bit integrity MAC key (bsc#1272731).
  • CVE-2026-59652: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (bsc#1272732).

Changes for bouncycastle:

Update to 1.85:

  • Additional Notes:

The standardised PQC algorithms ML-KEM, ML-DSA, SLH-DSA, FrodoKEM, and CMCE have been repackaged under org.bouncycastle.crypto and the versions under org.bouncycastle.crypto.pqc have been deprecated. These deprecated versions will be removed in BC 1.86.

References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
bouncycastle

Package

Name
bouncycastle
Purl
pkg:rpm/suse/bouncycastle&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.85-150200.3.38.1

Ecosystem specific

{
    "binaries":  [
        {
            "bouncycastle":  "1.85-150200.3.38.1",
            "bouncycastle-pg":  "1.85-150200.3.38.1",
            "bouncycastle-pkix":  "1.85-150200.3.38.1",
            "bouncycastle-util":  "1.85-150200.3.38.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3559-1.json"