CVE-2025-9341: Garbage collection can delay for AES CBC Native support, resulting in heap exhaustion
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java.
This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0.
Other sources
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java.
This issue affects Bouncy Castle for Java FIPS: 2.1.0; Bouncy Castle for Java LTS: from 2.73.0 through 2.73.7.
— MITRE
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java.
This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0; Bouncy Castle for Java LTS: from BC-LTS 2.73.0 through 2.73.7.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9341?
The severity of CVE-2025-9341 is critical due to the potential for excessive resource allocation.
How do I fix CVE-2025-9341?
To fix CVE-2025-9341, you should upgrade to a version of Bouncy Castle for Java FIPS that is not affected, specifically beyond version 2.1.0.
What causes CVE-2025-9341?
CVE-2025-9341 is caused by uncontrolled resource consumption related to excessive allocation in the AESNativeCBC.Java files.
What versions of Bouncy Castle are affected by CVE-2025-9341?
CVE-2025-9341 affects Bouncy Castle for Java FIPS version 2.1.0.
Is CVE-2025-9341 applicable to other products besides Bouncy Castle Java FIPS?
No, CVE-2025-9341 specifically affects the Bouncy Castle for Java FIPS API modules.