CVE-2025-9340: native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.
Published Aug 22, 2025
·Updated
Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher.
This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
Affected Software
2 affected componentsFixes available
Bouncy Castle Bouncy Castle for Java>=2.1.0<=2.1.0
maven/org.bouncycastle:bc-fips=2.1.0
2.1.1
Event History
Aug 22, 2025
CVE Published
via MITRE·09:39 AM
Data Sourced
via MITRE·09:39 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionWeaknessAffected Software
Feb 28, 57989
Event
via FIRST·03:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9340?
CVE-2025-9340 has a medium severity rating due to its potential for out-of-bounds write impacts.
2
How do I fix CVE-2025-9340?
To fix CVE-2025-9340, upgrade Bouncy Castle for Java to a version later than 2.1.0.
3
What are the potential impacts of CVE-2025-9340?
CVE-2025-9340 could lead to arbitrary code execution due to memory corruption from the out-of-bounds write.
4
Which versions of Bouncy Castle are affected by CVE-2025-9340?
CVE-2025-9340 affects Bouncy Castle for Java version 2.1.0.
5
Is CVE-2025-9340 a known issue in the Bouncy Castle library?
Yes, CVE-2025-9340 is a documented vulnerability within the Bouncy Castle library.