Back

CRITICAL

nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read

Published May 27, 2021

Description

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published May 27, 2021
Updated Aug 4, 2024
Reserved Apr 28, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 27, 2020
Bugzilla 1868931

ENISA EUVD

Assigner mozilla
Published May 27, 2021
Updated Aug 4, 2024

GitHub

No data