Closed Bug 2030561 Opened 5 months ago Closed 3 months ago

NULL pointer dereference in CERT_MergeExtensions

Categories

(NSS :: Libraries, defect, P3)

Tracking

(nss 3.125, firefox-esr115 wontfix, firefox-esr140 wontfix, firefox151 wontfix, firefox152 wontfix, firefox153 fixed)

RESOLVED FIXED
Tracking Status
nss --- 3.125
firefox-esr115 --- wontfix
firefox-esr140 --- wontfix
firefox151 --- wontfix
firefox152 --- wontfix
firefox153 --- fixed

People

(Reporter: bugmon, Assigned: anna.weine)

Details

(5 keywords, Whiteboard: [prefs-checked][sec-auto-downgraded][pp3][nss-nofx][adv-main153-])

Attachments

(3 files)

The CERT_MergeExtensions function in certxutl.c contains a NULL pointer dereference vulnerability at lines 374-375. The code evaluates a boolean expression that checks if ext->critical.len is non-zero before accessing ext->critical.data[ext->critical.len - 1], but fails to verify that ext->critical.data itself is non-NULL. This pattern is correctly validated in three other locations in the same file (lines 86, 460, 486) but was missed at the vulnerable location.

Build Info

Affected Code

File: security/nss/lib/certdb/certxutl.c, line 374-375

PRBool critical = (ext->critical.len != 0 && 
                   ext->critical.data[ext->critical.len - 1] != 0);

CERT_MergeExtensions function iterates through certificate extensions and accesses the critical field without proper NULL validation

Exploit Chain

  1. Attacker crafts a malformed CERTCertExtension with critical.len=1 and critical.data=NULL
  2. Code calls CERT_MergeExtensions with the malformed extension array
  3. Boolean expression evaluates critical.len first (non-zero, so evaluates second part)
  4. Dereferences NULL pointer: critical.data[critical.len - 1] becomes nullptr[0]
  5. AddressSanitizer detects SEGV at address 0x0
  6. Process terminates

Steps to Reproduce

  1. Create a CERTCertExtension struct
  2. Set critical.len to a non-zero value (e.g., 1)
  3. Set critical.data to nullptr
  4. Create an array of extensions containing the malformed extension
  5. Call CERT_MergeExtensions with the extension array
  6. Observe ASAN SEGV crash at address 0x0

Security Impact

  • Severity: High
  • Attacker capability: An attacker who can influence certificate extension structures (through malformed certificates, certificate injection, or API misuse) can trigger a NULL pointer dereference that crashes NSS
  • Preconditions: The attacker must be able to create or modify a CERTCertExtension structure where critical.len != 0 and critical.data == NULL, then pass it to CERT_MergeExtensions. This can occur through certificate processing, extension merging, or API abuse.

ASAN Report

AddressSanitizer:DEADLYSIGNAL
ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000
The signal is caused by a READ memory access.
Hint: address points to the zero page.
Crash in CERT_MergeExtensions at /firefox/security/dist/Release/lib/libnss3.so+0x117994
Attached file crash_stack.txt —
Group: core-security → crypto-core-security
Whiteboard: [prefs-checked][sec-auto-downgraded]

Prefs-checked: no prefs involved, NSS library code.

Downgrading sec-high: the crash is a guaranteed NULL pointer dereference (SEGV at 0x0 reading ext->critical.data[...] when data==NULL), which is not exploitable. Setting sec-other and removing csectype-wildptr.

This is an automated analysis result. If this result is incorrect please add a needinfo and feel free to correct the error.

Whiteboard: [prefs-checked][sec-auto-downgraded] → [prefs-checked][sec-auto-downgraded][pp3]

Unable to reproduce bug 2030561 using build mozilla-central 20260409040943-bb7e4d6d24f2. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Keywords: bugmon
Severity: -- → S4
Status: UNCONFIRMED → NEW
Ever confirmed: true
Priority: -- → P3
Whiteboard: [prefs-checked][sec-auto-downgraded][pp3] → [prefs-checked][sec-auto-downgraded][pp3] [nss-nofx]
Attached file (secure) —

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/31709ebb8d58
NULL pointer dereference in CERT_MergeExtensions r=nss-reviewers,jschanck

Status: NEW → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
Assignee: nobody → anna.weine
Group: crypto-core-security → core-security-release
status-nss: --- → 3.125
Whiteboard: [prefs-checked][sec-auto-downgraded][pp3] [nss-nofx] → [prefs-checked][sec-auto-downgraded][pp3] [nss-nofx][adv-main153+r]
Whiteboard: [prefs-checked][sec-auto-downgraded][pp3] [nss-nofx][adv-main153+r] → [prefs-checked][sec-auto-downgraded][pp3][nss-nofx][adv-main153-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: