PatchSiren cyber security CVE debrief
CVE-2026-8149 Legion of the Bouncy Castle Inc. CVE debrief
CVE-2026-8149 is a medium-severity issue in Legion of the Bouncy Castle Inc. BC-LTS that affects Linux x86_64 builds using AVX or AVX-512f-specific GCM program files. The supplied NVD record shows a local attack surface, low attack complexity, and low availability impact. Systems running BC-LTS from 2.73.0 through 2.73.10 should be treated as affected until upgraded.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-LTS
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-07-21
Who should care
Teams that package, deploy, or rely on Bouncy Castle BC-LTS on Linux x86_64 systems with AVX or AVX-512f support, especially if gcm128w or gcm512w binaries are installed or in use.
Technical summary
The NVD record describes a vulnerability in BC-LTS affecting Linux x86_64 AVX/AVX-512f program files gcm128w and gcm512w. The affected range is BC-LTS 2.73.0 through 2.73.10, with the fix boundary stated as before 2.73.11. The supplied CVSS v4.0 vector indicates local attack conditions, no privileges required, no user interaction, and a low availability impact, with no confidentiality or integrity impact recorded in the vector provided.
Defensive priority
Medium. Prioritize remediation for any Linux deployments that include the affected BC-LTS binaries, especially where cryptographic workloads are production-critical or broadly distributed.
Recommended defensive actions
- Upgrade BC-LTS to 2.73.11 or later.
- Inventory Linux x86_64 deployments for BC-LTS versions 2.73.0 through 2.73.10.
- Verify whether AVX/AVX-512f-optimized GCM binaries (gcm128w, gcm512w) are installed or invoked.
- Use the vendor-maintained advisory reference to confirm package-specific remediation and validation steps.
- If immediate upgrade is not possible, isolate affected hosts and monitor for unexpected instability in crypto-dependent services.
Evidence notes
The source corpus includes the NVD record, which names BC-LTS, lists the affected version range from 2.73.0 before 2.73.11, identifies the Linux/x86_64 AVX/AVX-512f program files, and provides a CVSS v4.0 vector showing local access and low availability impact. The only vendor reference included in the corpus is the bc-java GitHub wiki CVE page; no full advisory text was supplied, so remediation guidance is limited to the version boundary stated in the NVD description.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8149 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8149
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8149 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8149
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908149
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.