---
title: "CVE-2025-8916\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-8916?format=md
keywords: index, follow
---

# CVE-2025-8916

Publication date 13 August 2025

Last updated 17 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Allocation of Resources Without Limits or Throttling vulnerability in
Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules),
Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules),
Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API
modules) allows Excessive Allocation. This vulnerability is associated with
program files
https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java,
https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java.
This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44
through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through
2.0.7.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-8916?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bouncycastle | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Fixed 1.77-1ubuntu0.1~esm1  Ubuntu Pro |
| 22.04 LTS jammy | Ignored changes too intrusive |
| 20.04 LTS focal | Ignored changes too intrusive |
| 18.04 LTS bionic | Ignored changes too intrusive |
| 16.04 LTS xenial | Ignored end of ESM support, was ignored [changes too intrusive] |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-8916?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [hlibk](https://launchpad.net/~hlibk)

On jammy and below, the fix requires a previous refactor commit which
contains many changes and could introduce regressions. Relevant commit:
af130a29be3a1ecc7cf0e0f780fc7fc95795a9f1

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| bouncycastle | * Upstream:   [310b30a](https://github.com/bcgit/bc-java/commit/310b30a4fbf36d13f6cc201ffa7771715641e67e) * Upstream:   [ff444a4](https://github.com/bcgit/bc-java/commit/ff444a479942d88de64004dc82c3ee32a9e9075a) |

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8916)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-8916)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-8916)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-8916)

### Related Ubuntu Security Notices (USN)

+ [USN-8108-1](https://usn.ubuntu.com/USN-8108-1)
+ Bouncy Castle vulnerabilities
+ 18 March 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-8916>
* <https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%908916>
