CVE-2025-14813
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks
EPSS 0.31%
描述
The GOST 28147-2015 CTR mode implementation (`G3413CTRBlockCipher`) in the Legion of the Bouncy Castle BC-JAVA `bcprov` core module only increments the final byte of the counter, so the counter wraps after 255 blocks and the keystream is reused. Reusing CTR keystream allows an attacker who can observe two ciphertexts produced with the same key/IV to recover the XOR of the plaintexts, breaking confidentiality. Affects BC-JAVA from 1.59 before 1.84 (with backported fixes in 1.80.2 and 1.81.1).
如何修補 CVE-2025-14813
要修補 CVE-2025-14813,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.80.2 或更新版本
CVE-2025-14813 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(12)
- >= 1.59, <= 1.80.1
- >= 1.59, <= 1.80.1
- >= 1.59, <= 1.80.1
- >= 1.59, <= 1.74
- >= 1.59, <= 1.77
- >= 1.59, <= 1.77
- >= 1.59, <= 1.78.1
- >= 1.59, <= 1.78.1
- >= 1.59, <= 1.78.1
- >= 1.59, <= 1.80.1
- >= 1.59, <= 1.80.1
- >= 1.59, < 1.80.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red |