X25519MLKEM768 "removed" by alert injection
Categories
(Core :: Security: PSM, defect)
Tracking
()
People
(Reporter: 1foobar, Unassigned)
Details
(Keywords: reporter-external, Whiteboard: [client-bounty-form])
Attachments
(3 files)
Background
I was researching the topic of TLS version downgrade attacks and wanted to deepen my understanding of countermeasures by examining software that uses TLS. I discovered a mechanism to remove the X25519MLKEM769 key exchange method that is the most preferred one by default.
Overview
Firefox retries three times to establish a TLS connection upon consistently receiving a TLS close_notify alert as response to Firefox's Client Hello messages. The key share entry X25519MLKEM768 is missing in the fourth Client Hello sent by Firefox.
Tested Versions
- Firefox Nightly 148.0a1 (2025-12-30) (64-bit Linux)
- Firefox Version 140.4.0esr (64-bit Linux)
close_notify alert
The alert response is the following:
- close_notify alert in bytes
0x15 0x03 0x01 0x00 0x02 0x02 0x00- Content Type: Alert (0x15)
- TLS Version 1.0 (0x0301)
- Length (0x00 0x02)
- Level: Fatal (0x02)
- Alert Type (0x00) (close_notify)
Provided POC
Responds with a close_notify alert to any connection made.
- Listens on
0.0.0.0 - Default Port is
443- Custom port via
-p <port>flag
- Custom port via
Running
- I use
go1.25.4 linux/amd64- Other versions should be fine
- Run via e.g.
go run poc.go
Steps to reproduce:
(Create a new default profile in Firefox)
- Start the provided or your own POC
- Capture the traffic to the listening port of the POC via e.g. Wireshark
- Open a new Firefox instance
- Connect to the POC via https://poc-addr:port
- Inspect and compare the captured
Client HellomessagesX25519MLKEM768has been removed from the key share entries of the lastClient Hellosent.
Sidenotes
- Only one retry is made if the refresh button is clicked instead of starting a new Firefox instance.
X25519MLKEM768is missing in the retry. - I would have provided screenshots but the form allows only for a single file
Updated•9 months ago
|
Comment 3•9 months ago
|
||
I believe this is the expected behavior while we work out any compatibility issues. John - I'll close this as invalid and mark it not security-sensitive unless you want to handle it another way.
Comment 4•9 months ago
|
||
I opened Bug 2008597 to track removal of the retry mechanism. So we could remove the security flag here and mark this as a duplicate of 2008597.
Updated•9 months ago
|
Updated•9 months ago
|
Description
•