UBUNTU-CVE-2026-13505

Source
https://ubuntu.com/security/CVE-2026-13505
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-13505
Upstream
  • CVE-2026-13505
Published
2026-08-08T02:17:00Z
Modified
2026-08-13T00:02:16Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD and scrypt parameter classes was zeroised on garbage collection by overriding Object.finalize. Finalization runs at an unspecified time and in an unspecified order and is serviced by a single finalizer thread, so where objects carrying a finalizer are allocated faster than that thread retires them the pending-finalization queue grows without bound: disposal falls arbitrarily far behind, which can contribute to an OutOfMemoryError under load, and the key material those objects hold stays resident in the heap for as long as they are queued, defeating the purpose of the zeroisation. The behaviour was not a problem on Java 8 or Java 11; it is later JVMs, on which finalization has been deprecated and progressively de-emphasised, where it becomes one. Disposal of these classes now runs from a java.lang.ref.Cleaner registered in the multi-release jdk1.9 overlay, so on Java 9 and later it no longer depends on the finalizer being scheduled. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected, as neither implements the finalizer-based zeroisation scheme.

References

Affected packages

Ubuntu:26.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.80-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcjmail-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcprov-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbctls-java"
        },
        {
            "binary_version": "1.80-3",
            "binary_name": "libbcutil-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"
Ubuntu:Pro:16.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.49+dfsg-3ubuntu1
1.51-4ubuntu1
1.51-4ubuntu1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.51-4ubuntu1+esm1",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.51-4ubuntu1+esm1",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.51-4ubuntu1+esm1",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.51-4ubuntu1+esm1",
            "binary_name": "libbcprov-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"
Ubuntu:Pro:18.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.57-1
1.58-1
1.59-1
1.59-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.59-1ubuntu0.1~esm1",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.59-1ubuntu0.1~esm1",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.59-1ubuntu0.1~esm1",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.59-1ubuntu0.1~esm1",
            "binary_name": "libbcprov-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"
Ubuntu:Pro:20.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.61-1
1.61-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.61-1ubuntu0.1~esm1",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.61-1ubuntu0.1~esm1",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.61-1ubuntu0.1~esm1",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.61-1ubuntu0.1~esm1",
            "binary_name": "libbcprov-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"
Ubuntu:Pro:22.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.68-2
1.68-4
1.68-5
1.68-5ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.68-5ubuntu0.1~esm1",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.68-5ubuntu0.1~esm1",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.68-5ubuntu0.1~esm1",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.68-5ubuntu0.1~esm1",
            "binary_name": "libbcprov-java"
        },
        {
            "binary_version": "1.68-5ubuntu0.1~esm1",
            "binary_name": "libbctls-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"
Ubuntu:Pro:24.04:LTS
bouncycastle

Package

Name
bouncycastle
Purl
pkg:deb/ubuntu/bouncycastle?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.72-2
1.77-1
1.77-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcjmail-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcmail-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcpg-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcpkix-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcprov-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbctls-java"
        },
        {
            "binary_version": "1.77-1ubuntu0.1~esm1",
            "binary_name": "libbcutil-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13505.json"