First published: Tue Aug 06 2024(Updated: )
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/nss | <=2:3.61-1+deb11u3<=2:3.87.1-1 | 2:3.105-2 |
Firefox | <129 | 129 |
Firefox | <129.0 | |
Firefox ESR | <115.14.0 | |
Firefox ESR | =128.0 | |
Firefox ESR | <115.14 | 115.14 |
Firefox ESR | <128.1 | 128.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-7531 has a high severity rating due to the potential exposure of plaintext data.
To mitigate CVE-2024-7531, upgrade to Mozilla Firefox versions 129 or later or Firefox ESR versions 115.14 or later.
CVE-2024-7531 affects Firefox versions up to 129 and Firefox ESR versions up to 128.1.
CVE-2024-7531 can lead to sensitive information exposure when using the ChaCha20-Poly1305 cipher suite in Firefox.
The best approach for CVE-2024-7531 is to update to the recommended versions, as there are no specific workarounds.