CVE-2025-9340 | Bouncy Castle for Java up to 2.1.0 API Module BaseCipher out-of-bounds write (EUVD-2025-25505 / WID-SEC-2025-1895)
A vulnerability categorized as critical has been discovered in Bouncy Castle for Java up to 2.1.0. This issue affects some unknown processing of the file org/bouncycastle/jcajce/provider/BaseCipher of the component API Module. Executing manipulation can lead to out-of-bounds write.
This vulnerability appears as CVE-2025-9340. It is feasible to perform the attack on the physical device. There is no available exploit.