---
title: CVE-2026-85515
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-85515
---

# CVE-2026-85515

Publication date 5 October 2026

Last updated 5 October 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted
message was accepted with no error reported, and on the SEIPD version 1
path with no integrity check performed at all. RFC 9580 sec. 13.7 permits
an implementation to release the cleartext of the fully authenticated
chunks when streaming but requires it to indicate a clear error as soon as
the truncation is detected, and to report suspect integrity when it
discovers malleable ciphertext. The truncation was detected and then
discarded: when a message is truncated but the length field of the
enclosing packet is left unchanged, BCPGInputStream.PartialInputStream
raises an EOFException for the missing ciphertext, and
BCPGInputStream.nextPacketTag() reports an EOFException as a clean end of
message, so the packet stream above it stopped as though no packets
remained. On the AEAD path (SEIPD version 2 and the version 5 AEAD packet),
when the literal data packet ended on an AEAD chunk boundary and the
consumer read in increments smaller than one chunk, the look-ahead for the
packet after the literal triggered the truncated chunk read, so BcAEADUtil
and JceAEADUtil never reached the trailing message tag of sec. 5.13.2 that
authenticates the total plaintext length; the caller received the plaintext
of the fully authenticated chunks, every packet following the literal was
silently dropped, and no exception was raised, so a signed and encrypted
message read back as a well-formed unsigned one. Every byte released on
that path remained individually authenticated, making this a missing
truncation error rather than a forgery, and it is a residual of
CVE-2026-12817, which closed the same outcome for an attacker who corrects
the outer packet length. On the SEIPD version 1 path the consequence was
more serious: IntegrityProtectedInputStream verifies the modification
detection code from close(), and reached close() only by closing itself
when a read of it returned -1, which a truncated message never produces, so
PGPEncryptedData.verify() never ran and the recipient was handed
CFB-decrypted plaintext on which no integrity check of any kind had been
performed. Measured on a message truncated into that shape, 136 distinct
single-byte modifications of the ciphertext produced accepted, altered
plaintext with no exception raised. Reachability is a property of the
message rather than of attacker-supplied input: the AEAD shape held for 3
of 131 consecutive payload lengths measured, and the SEIPD version 1 shape
for one payload length in sixteen, at a truncation offset that did not move
with the payload length. The low-level API is unaffected, a caller that
invokes PGPEncryptedData.verify() directly getting the check regardless, as
are consumers reading in increments of a whole AEAD chunk or more. The AEAD
decryption streams now re-throw such an EOFException as a plain
IOException, which nextPacketTag() does not launder;
OpenPGPMessageInputStream.close() now closes its layer's
integrity-protected stream itself rather than relying on that stream having
seen the end of its data; and IntegrityProtectedInputStream.close() was
made idempotent, as java.io.Closeable requires, which that depends on,
since the stream is genuinely closed twice on the ordinary path and
PGPEncryptedData.verify() consumes the digest state behind it and cannot be
run a second time. This issue also affects Bouncy Castle for Java LTS
before 2.73.13, on the AEAD route only, as that edition does not ship the
high-level OpenPGP API the SEIPDv1 route runs through. It also affects
Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.14 (1.0.X
series), 2.0.14.1 (2.0.X series) and 2.1.14 (2.1.X series), on the AEAD
route only, as those editions do not ship the high-level OpenPGP API.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bouncycastle | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

8.2 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | High |
  | Vulnerable system - Availability impact | None |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.2 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-85515)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-85515)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-85515)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-85515)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-85515>
* <https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9085515>
* <https://github.com/bcgit/bc-java/commit/ab7a235d1c20e3da28ce77167a96b5c14025efa7>
