What is CVE-2026-8798?
In Bouncy Castle for Java FIPS (BC-FJA) before version bc-fips 2.1.3, the native entropy source on Intel platforms retries RDSEED and RDRAND CPU instructions without any bound. This may lead to an infinite loop. Users should update to bc-fips 2.1.3 or later to mitigate the issue.
Azərbaycanca: Bouncy Castle for Java FIPS (BC-FJA) kitabxanasında, bc-fips 2.1.3 versiyasından əvvəl, Intel platformalarında istifadə olunan native entropy source RDSEED və RDRAND təlimatlarını heç bir məhdudiyyət olmadan təkrar çağırır. Bu, sonsuz döngüyə səbəb ola bilər. Təhlükəsizliyi təmin etmək üçün kitabxananı ən azı bc-fips 2.1.3 versiyasına yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Bouncy Castle
FAQ2
Which product is affected by this vulnerability?
CVE-2026-8798 affects Bouncy Castle for Java FIPS (BC-FJA) library versions prior to bc-fips 2.1.3.
How can this issue be mitigated?
Users should update to bc-fips 2.1.3 or later to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.