{"id":"CVE-2025-14813","summary":"GOSTCTR implementation unable to process more than 255 blocks correctly","details":": Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).\n\n This vulnerability is associated with program files G3413CTRBlockCipher.\n\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.","aliases":["GHSA-574f-3g2m-x479"],"modified":"2026-08-08T09:38:17.319345Z","published":"2026-04-15T08:56:34.057Z","related":["CGA-hv3g-4gqh-c5fc","SUSE-SU-2026:1639-1","SUSE-SU-2026:21404-1","openSUSE-SU-2026:10571-1","openSUSE-SU-2026:20627-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1.59"},{"fixed":"1.80.2"},{"introduced":"1.81"},{"fixed":"1.81.1"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"bcorg","cwe_ids":["CWE-327"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14813.json"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json"},{"type":"WEB","url":"https://www.bouncycastle.org/download/bouncy-castle-java/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:11720"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:11721"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13631"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14272"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:14276"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:17668"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18054"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18055"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18059"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:21772"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24977"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-14813"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14813.json"},{"type":"ADVISORY","url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14813"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458640"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f"},{"type":"PACKAGE","url":"https://github.com/bcgit/bc-java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"de42702b6cda2631e8e3ff94f8458198860b328e"},{"fixed":"d716d7716a452bad283323aefd88ff21eba8deef"},{"fixed":"701686cb0184cd9ae103c801b3581fdf95c6d4f3"},{"fixed":"b42574345414e4b7c8051b16fa1fafe01c29871f"}],"database_specific":{"extracted_events":[{"introduced":"1.82"},{"fixed":"1.84"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["r1rv83","r1rv82"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14813.json","vanir_signatures_modified":"2026-08-08T09:38:17Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["262386939091886332078283368458154035620","241903356408364102397713104555431676338","237104995760111515567516545948185958019","260088556733241009645093216339235896362","5279621054392667723777881444889999928","324944887105293821129491217626875010557","270453564589089163720850664440047201843","329322209623640002993202889481694352444","66155707311067247870190037078741720121","161374838074741889965706815960646264073"],"threshold":0.9},"id":"CVE-2025-14813-5c2066ec","signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","target":{"file":"core/src/test/java/org/bouncycastle/crypto/test/GOST3412Test.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","target":{"file":"core/src/main/java/org/bouncycastle/crypto/modes/G3413CTRBlockCipher.java","function":"generateCRT"},"deprecated":false,"digest":{"function_hash":"135703389312834859365583448199898207812","length":52},"id":"CVE-2025-14813-b573c35e"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","target":{"file":"core/src/main/java/org/bouncycastle/crypto/modes/G3413CTRBlockCipher.java"},"deprecated":false,"digest":{"line_hashes":["300276481577487608390511461847156506634","72522421026871186003987298727235672255","248267566282422170437507320289939179897","138697558518558829764409570695921082925","77795620714087101855215776586887480360","253117628173900454412939023697079452098","208234895684152768712941298085623426170","135859151753741312629440454464083697812","34657907477393269367890762234709985303","162613496227733929556244931463578218449","23508661060569098979606906785804307616","205494679626699834684157133405272565850","270832754347741209623177904078690096985","44411157617046897982588222964373660319","243716333709493041231698108128808029013","287610177451687686823260933424799021201","42582010187046702125651359236594596468","76149004579646775163727134742480470349","211854039433732041274137846380870222224","87129416677021730283748693137420676406","180478707998351201328850126237475280813","335503892522674268647705888493576315498"],"threshold":0.9},"id":"CVE-2025-14813-db0baff6"},{"signature_version":"v1","source":"https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","target":{"file":"core/src/test/java/org/bouncycastle/crypto/test/GOST3412Test.java","function":"performTest"},"deprecated":false,"digest":{"length":62,"function_hash":"75074325176343452193019954033376254166"},"id":"CVE-2025-14813-e313969d","signature_type":"Function"}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red"}]}