nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read
Published May 27, 2021
9.1
CRITICALCVSS 3.1
EPSS 1.54%
Description
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.
Affected products
- Vendor n/a Product Nss Defaultunknown
Affected
- nss 3.55
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Nss | unknown | Affected
|
No data.
Red Hat Enterprise Linux 7
nspr-0:4.25.0-2.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-0:3.53.1-3.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-softokn-0:3.53.1-6.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-util-0:3.53.1-1.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7.4 Advanced Update Support
nss-softokn-0:3.28.3-10.el7_4
Fixed · RHSA-2021:0758
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
nss-softokn-0:3.28.3-10.el7_4
Fixed · RHSA-2021:0758
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
nss-softokn-0:3.28.3-10.el7_4
Fixed · RHSA-2021:0758
Red Hat Enterprise Linux 7.6 Extended Update Support
nss-0:3.36.0-9.el7_6
Fixed · RHSA-2021:0876
Red Hat Enterprise Linux 7.6 Extended Update Support
nss-softokn-0:3.36.0-7.el7_6
Fixed · RHSA-2021:0876
Red Hat Enterprise Linux 7.7 Extended Update Support
nss-softokn-0:3.44.0-9.el7_7
Fixed · RHSA-2021:1026
Red Hat Enterprise Linux 8
nss-0:3.53.1-17.el8_3
Fixed · RHSA-2021:0538
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat Enterprise Linux 5
nss
Out of support scope
Red Hat Enterprise Linux 6
nss
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | nspr-0:4.25.0-2.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-0:3.53.1-3.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-softokn-0:3.53.1-6.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-util-0:3.53.1-1.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | nss-softokn-0:3.28.3-10.el7_4 | Fixed | RHSA-2021:0758 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | nss-softokn-0:3.28.3-10.el7_4 | Fixed | RHSA-2021:0758 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | nss-softokn-0:3.28.3-10.el7_4 | Fixed | RHSA-2021:0758 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | nss-0:3.36.0-9.el7_6 | Fixed | RHSA-2021:0876 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | nss-softokn-0:3.36.0-7.el7_6 | Fixed | RHSA-2021:0876 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | nss-softokn-0:3.44.0-9.el7_7 | Fixed | RHSA-2021:1026 |
| Red Hat Enterprise Linux 8 | nss-0:3.53.1-17.el8_3 | Fixed | RHSA-2021:0538 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat Enterprise Linux 5 | nss | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | nss | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-12403 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1868931 Issue TrackingPatchThird Party Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4715 Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00021.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2020-12403
- https://security.netapp.com/advisory/ntap-20230324-0006/
- https://www.cve.org/CVERecord?id=CVE-2020-12403
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-12403 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1868931 | Issue TrackingPatchThird Party Advisory | |
| https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4715 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/02/msg00021.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-12403 | ||
| https://security.netapp.com/advisory/ntap-20230324-0006/ | ||
| https://www.cve.org/CVERecord?id=CVE-2020-12403 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data