Closed Bug 2008015 Opened 9 months ago Closed 9 months ago

X25519MLKEM768 "removed" by alert injection

Categories

(Core :: Security: PSM, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 2008597

People

(Reporter: 1foobar, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [client-bounty-form])

Attachments

(3 files)

Attached file poc.go —

Background

I was researching the topic of TLS version downgrade attacks and wanted to deepen my understanding of countermeasures by examining software that uses TLS. I discovered a mechanism to remove the X25519MLKEM769 key exchange method that is the most preferred one by default.

Overview

Firefox retries three times to establish a TLS connection upon consistently receiving a TLS close_notify alert as response to Firefox's Client Hello messages. The key share entry X25519MLKEM768 is missing in the fourth Client Hello sent by Firefox.

Tested Versions

  • Firefox Nightly 148.0a1 (2025-12-30) (64-bit Linux)
  • Firefox Version 140.4.0esr (64-bit Linux)

close_notify alert

The alert response is the following:

  • close_notify alert in bytes 0x15 0x03 0x01 0x00 0x02 0x02 0x00
    • Content Type: Alert (0x15)
    • TLS Version 1.0 (0x0301)
    • Length (0x00 0x02)
    • Level: Fatal (0x02)
    • Alert Type (0x00) (close_notify)

Provided POC

Responds with a close_notify alert to any connection made.

  • Listens on 0.0.0.0
  • Default Port is 443
    • Custom port via -p <port> flag

Running

  • I use go1.25.4 linux/amd64
    • Other versions should be fine
  • Run via e.g. go run poc.go

Steps to reproduce:

(Create a new default profile in Firefox)

  1. Start the provided or your own POC
  2. Capture the traffic to the listening port of the POC via e.g. Wireshark
  3. Open a new Firefox instance
  4. Connect to the POC via https://poc-addr:port
  5. Inspect and compare the captured Client Hello messages
    • X25519MLKEM768 has been removed from the key share entries of the last Client Hello sent.

Sidenotes

  1. Only one retry is made if the refresh button is clicked instead of starting a new Firefox instance. X25519MLKEM768 is missing in the retry.
  2. I would have provided screenshots but the form allows only for a single file
Flags: sec-bounty?
Group: firefox-core-security → crypto-core-security
Component: Security → Security: PSM
Product: Firefox → Core

I believe this is the expected behavior while we work out any compatibility issues. John - I'll close this as invalid and mark it not security-sensitive unless you want to handle it another way.

Flags: needinfo?(jschanck)

I opened Bug 2008597 to track removal of the retry mechanism. So we could remove the security flag here and mark this as a duplicate of 2008597.

Flags: needinfo?(jschanck)
Group: crypto-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 9 months ago
Duplicate of bug: 2008597
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: