VDB
RHSA-2026%3A12269
RHSA-2026%3A12269
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA core. A covert timing channel vulnerability, caused by non-constant time comparisons, risks the leakage of private keys in the FrodoKEM implementation. An unauthenticated, remote attacker can potentially exploit this timing discrepancy to gain unauthorized access to sensitive cryptographic information.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 |
Timeline
- Apr 30, 2026 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 18, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:12269 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://access.redhat.com/articles/7137599 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458635 issue
- https://issues.redhat.com/browse/JBEAP-32774 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_12269.json advisory
- https://access.redhat.com/security/cve/CVE-2026-5598 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-5598 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5598 advisory
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905998 advisory