Bugzilla – Bug 1224304
VUL-0: CVE-2024-30172: bouncycastle: infinite loop triggered via a crafted signature and public key
Last modified: 2024-06-26 10:30:35 UTC
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. References: https://www.bouncycastle.org/latest_releases.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-30172 https://www.cve.org/CVERecord?id=CVE-2024-30172
More information on the fix can be found here: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030172