CVE-2024-7531: Medium severity firefox vulnerability
Calling PK11Encrypt() in NSS using CKMCHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
Other sources
Calling PK11Encrypt() in NSS using CKMCHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7531?
CVE-2024-7531 has a high severity rating due to the potential exposure of plaintext data.
How do I fix CVE-2024-7531?
To mitigate CVE-2024-7531, upgrade to Mozilla Firefox versions 129 or later or Firefox ESR versions 115.14 or later.
Which versions of Firefox are affected by CVE-2024-7531?
CVE-2024-7531 affects Firefox versions up to 129 and Firefox ESR versions up to 128.1.
What is the impact of CVE-2024-7531?
CVE-2024-7531 can lead to sensitive information exposure when using the ChaCha20-Poly1305 cipher suite in Firefox.
Is there a workaround for CVE-2024-7531?
The best approach for CVE-2024-7531 is to update to the recommended versions, as there are no specific workarounds.