PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8149 Legion of the Bouncy Castle Inc. CVE debrief

CVE-2026-8149 is a medium-severity issue in Legion of the Bouncy Castle Inc. BC-LTS that affects Linux x86_64 builds using AVX or AVX-512f-specific GCM program files. The supplied NVD record shows a local attack surface, low attack complexity, and low availability impact. Systems running BC-LTS from 2.73.0 through 2.73.10 should be treated as affected until upgraded.

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-LTS
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-07-21
Advisory published
2026-05-08
Advisory updated
2026-07-21

Who should care

Teams that package, deploy, or rely on Bouncy Castle BC-LTS on Linux x86_64 systems with AVX or AVX-512f support, especially if gcm128w or gcm512w binaries are installed or in use.

Technical summary

The NVD record describes a vulnerability in BC-LTS affecting Linux x86_64 AVX/AVX-512f program files gcm128w and gcm512w. The affected range is BC-LTS 2.73.0 through 2.73.10, with the fix boundary stated as before 2.73.11. The supplied CVSS v4.0 vector indicates local attack conditions, no privileges required, no user interaction, and a low availability impact, with no confidentiality or integrity impact recorded in the vector provided.

Defensive priority

Medium. Prioritize remediation for any Linux deployments that include the affected BC-LTS binaries, especially where cryptographic workloads are production-critical or broadly distributed.

Recommended defensive actions

  • Upgrade BC-LTS to 2.73.11 or later.
  • Inventory Linux x86_64 deployments for BC-LTS versions 2.73.0 through 2.73.10.
  • Verify whether AVX/AVX-512f-optimized GCM binaries (gcm128w, gcm512w) are installed or invoked.
  • Use the vendor-maintained advisory reference to confirm package-specific remediation and validation steps.
  • If immediate upgrade is not possible, isolate affected hosts and monitor for unexpected instability in crypto-dependent services.

Evidence notes

The source corpus includes the NVD record, which names BC-LTS, lists the affected version range from 2.73.0 before 2.73.11, identifies the Linux/x86_64 AVX/AVX-512f program files, and provides a CVSS v4.0 vector showing local access and low availability impact. The only vendor reference included in the corpus is the bc-java GitHub wiki CVE page; no full advisory text was supplied, so remediation guidance is limited to the version boundary stated in the NVD description.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8149 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8149

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8149 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8149

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908149

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.