Inconsistency between implementation and documented design in Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS - CVE-2026-8149

 

Inconsistency between implementation and documented design in Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS - CVE-2026-8149

Published: May 25, 2026


Vulnerability identifier: #VU132272
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8149
CWE-ID: CWE-1068
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise cryptographic integrity.

The vulnerability exists due to inconsistency between implementation and documented design in gcm128w and gcm512w when performing GCM operations on Linux x86_64 systems with AVX or AVX-512f support. A remote attacker can trigger the affected cryptographic code path to compromise cryptographic integrity.

Only Linux x86_64 environments with AVX or AVX-512f support are affected.


Affected software

Bouncy Castle for Java FIPS
Bouncy Castle for Java LTS
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server

How to mitigate CVE-2026-8149

Install security update from vendor's website.

Bouncy Castle for Java FIPS - update to 2.1.2
Bouncy Castle for Java LTS - update to 2.73.11
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01

External References

Related Security Bulletins