{"id":"GHSA-vc8p-8pxg-rfwg","summary":"ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing","details":"## Summary\n\nThe DER parser used for application-supplied private keys did not safely validate encoded length values before converting them to `Int` values or allocating arrays.\n\nA malformed private-key file could encode a length that overflowed or wrapped around, or request an allocation much larger than the available input. This could cause parsing errors or an uncaught `OutOfMemoryError`, potentially terminating the application process.\n\n## Details\n\nThe issue was in `DerReader.readLength()` and primitive readers such as `readInteger()`.\n\n`readLength()` previously accepted up to 127 length octets and accumulated them into an `Int`:\n\n```kotlin\nlength = (length shl 8) or nextByte\n```\n\nThis permitted integer overflow. For example:\n\n- `0x1_0000_0001` wrapped to `1`.\n- `0x8000_0000` wrapped to `Int.MIN_VALUE`.\n\nPrimitive readers then allocated memory based on the resulting value without first checking it against the remaining input:\n\n```kotlin\nval bytes = ByteArray(length)\ndata.get(bytes)\n```\n\nA six-byte DER value declaring a 1 GiB INTEGER caused an immediate `OutOfMemoryError` when tested with a constrained JVM heap. Because `OutOfMemoryError` is not an `Exception`, it is not caught by the public-key authentication error handling and may terminate the application process.\n\nA zero-length DER INTEGER is also invalid, but it does not produce `BigInteger.ZERO`: Java throws `NumberFormatException` when constructing a `BigInteger` from an empty byte array. No weakened or usable cryptographic key has been demonstrated through this issue.\n\n## Attack Requirements\n\nThe affected DER parser processes private-key material explicitly supplied by the application through APIs such as:\n\n- `SshClient.authenticatePublicKey()`\n- `SshKeys.decodePemPrivateKey()`\n- `SshSigning.sign()`\n- `SshSigning.getPublicKey()`\n\nThe DER input is not populated from SSH server host keys or agent-forwarding requests. Exploitation therefore requires a user or application to load an attacker-provided private-key file. The issue is not remotely exploitable by an SSH server.\n\n## Impact\n\nSuccessful exploitation can cause:\n\n- Incorrect DER length interpretation due to integer wraparound\n- Excessive memory allocation\n- An uncaught `OutOfMemoryError`\n- Loss of availability of the affected application process\n\nThere is no demonstrated confidentiality or integrity impact.\n\n## Remediation\n\nThe DER parser now:\n\n- Rejects indefinite lengths\n- Explicitly limits long-form lengths to `Int.SIZE_BYTES` (four octets) and rejects values above `Int.MAX_VALUE`\n- Accumulates long-form lengths in a `Long` before converting to `Int`\n- Rejects truncated and non-minimal length encodings\n- Checks declared lengths against the remaining input before allocation or advancing the input position\n- Rejects zero-length DER INTEGER, BIT STRING, and OBJECT IDENTIFIER values where an empty encoding is invalid\n- Rejects non-canonical DER INTEGER encodings with redundant sign octets\n\nThe bounds checks are implemented in shared DER reader helpers and apply to INTEGER, OCTET STRING, BIT STRING, OBJECT IDENTIFIER, SEQUENCE, context-specific values, and skipped values. PKCS#1 RSA and SEC1 EC private keys pass application-supplied DER directly through these helpers. PKCS#8 input is parsed by the JCA provider, and OpenSSH private keys use a separate wire-format parser rather than `DerReader`.","aliases":["CVE-2026-54697"],"modified":"2026-07-08T17:56:37.718101Z","published":"2026-06-12T21:02:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-12T21:02:15Z","nvd_published_at":null,"cwe_ids":["CWE-190","CWE-789"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/connectbot/cbssh/security/advisories/GHSA-vc8p-8pxg-rfwg"},{"type":"PACKAGE","url":"https://github.com/connectbot/cbssh"},{"type":"WEB","url":"https://github.com/connectbot/cbssh/releases/tag/v0.3.1"}],"affected":[{"package":{"name":"org.connectbot.sshlib:sshlib","ecosystem":"Maven","purl":"pkg:maven/org.connectbot.sshlib/sshlib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.3.0"}]}],"versions":["0.1.2","0.1.3","0.1.4","0.2.0","0.2.1","0.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-vc8p-8pxg-rfwg/GHSA-vc8p-8pxg-rfwg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}