|
|
Message-ID: <41a8fff9-9180-477e-b872-e22f86684603@oracle.com>
Date: Tue, 4 Aug 2026 10:23:23 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com, Peter Gutmann <pgut001@...auckland.ac.nz>
Subject: Re: Bouncy Castle 1.85 release fixes 32 CVEs
On 8/3/2026 7:37 PM, Peter Gutmann wrote:
> Alan Coopersmith <alan.coopersmith@...cle.com> writes:
>
>> It also says the release contains fixes for the following CVEs:
>
> Given the quantity and sweeping scope of those, was this the result of some
> new tool used for code analysis? I'm assuming AI, it sounds like there'd be
> an interesting backstory to how all of this was turned up.
I didn't see anything in the announcements from the Bouncy Castle folks
about that.
They do have more info about the CVE's in their wiki, such as:
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
but I don't see any reference there to how they were found/reported.
--
-Alan Coopersmith- alan.coopersmith@...cle.com
Oracle Solaris Engineering - https://blogs.oracle.com/solaris
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.