Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-firefoxamazon-linux-ami-2-upgrade-firefox-debuginfo | Sep 19, 2024 | Aug 6, 2024 | |
| Debian | debian-upgrade-firefox-esr | Aug 8, 2024 | Aug 6, 2024 | |
| Freebsd | freebsd-upgrade-package-firefox | Aug 14, 2024 | Aug 13, 2024 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-lang-spidermonkeygentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bingentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Dec 9, 2024 | Aug 6, 2024 | |
| Mfsa2024 33 | mozilla-firefox-upgrade-129_0 | Aug 7, 2024 | Aug 6, 2024 | |
| Mfsa2024 34 | mozilla-firefox-esr-upgrade-115_14 | Aug 7, 2024 | Aug 6, 2024 | |
| Mfsa2024 35 | mozilla-firefox-esr-upgrade-128_1 | Aug 7, 2024 | Aug 6, 2024 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Aug 6, 2024 |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-slesuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-other | Aug 14, 2024 | Aug 6, 2024 |
| Ubuntu | ubuntu-upgrade-firefox | Aug 20, 2024 | Aug 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub