NULL pointer dereference in CERT_MergeExtensions
Categories
(NSS :: Libraries, defect, P3)
Tracking
(nss 3.125, firefox-esr115 wontfix, firefox-esr140 wontfix, firefox151 wontfix, firefox152 wontfix, firefox153 fixed)
People
(Reporter: bugmon, Assigned: anna.weine)
Details
(5 keywords, Whiteboard: [prefs-checked][sec-auto-downgraded][pp3][nss-nofx][adv-main153-])
Attachments
(3 files)
The CERT_MergeExtensions function in certxutl.c contains a NULL pointer dereference vulnerability at lines 374-375. The code evaluates a boolean expression that checks if ext->critical.len is non-zero before accessing ext->critical.data[ext->critical.len - 1], but fails to verify that ext->critical.data itself is non-NULL. This pattern is correctly validated in three other locations in the same file (lines 86, 460, 486) but was missed at the vulnerable location.
Build Info
- Branch: main
- Revision: 07e27bfce5acf193bdb89c7ba2aa73451a3e43b4
- Timestamp: 2026-04-07T18:06:29+00:00
Affected Code
File: security/nss/lib/certdb/certxutl.c, line 374-375
PRBool critical = (ext->critical.len != 0 &&
ext->critical.data[ext->critical.len - 1] != 0);
CERT_MergeExtensions function iterates through certificate extensions and accesses the critical field without proper NULL validation
Exploit Chain
- Attacker crafts a malformed CERTCertExtension with critical.len=1 and critical.data=NULL
- Code calls CERT_MergeExtensions with the malformed extension array
- Boolean expression evaluates critical.len first (non-zero, so evaluates second part)
- Dereferences NULL pointer: critical.data[critical.len - 1] becomes nullptr[0]
- AddressSanitizer detects SEGV at address 0x0
- Process terminates
Steps to Reproduce
- Create a CERTCertExtension struct
- Set critical.len to a non-zero value (e.g., 1)
- Set critical.data to nullptr
- Create an array of extensions containing the malformed extension
- Call CERT_MergeExtensions with the extension array
- Observe ASAN SEGV crash at address 0x0
Security Impact
- Severity: High
- Attacker capability: An attacker who can influence certificate extension structures (through malformed certificates, certificate injection, or API misuse) can trigger a NULL pointer dereference that crashes NSS
- Preconditions: The attacker must be able to create or modify a CERTCertExtension structure where critical.len != 0 and critical.data == NULL, then pass it to CERT_MergeExtensions. This can occur through certificate processing, extension merging, or API abuse.
ASAN Report
AddressSanitizer:DEADLYSIGNAL
ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000
The signal is caused by a READ memory access.
Hint: address points to the zero page.
Crash in CERT_MergeExtensions at /firefox/security/dist/Release/lib/libnss3.so+0x117994
| Reporter | ||
Comment 1•5 months ago
|
||
| Reporter | ||
Comment 2•5 months ago
|
||
Updated•5 months ago
|
Updated•5 months ago
|
Comment 4•5 months ago
|
||
Prefs-checked: no prefs involved, NSS library code.
Downgrading sec-high: the crash is a guaranteed NULL pointer dereference (SEGV at 0x0 reading ext->critical.data[...] when data==NULL), which is not exploitable. Setting sec-other and removing csectype-wildptr.
This is an automated analysis result. If this result is incorrect please add a needinfo and feel free to correct the error.
Updated•5 months ago
|
| Reporter | ||
Comment 6•5 months ago
|
||
Unable to reproduce bug 2030561 using build mozilla-central 20260409040943-bb7e4d6d24f2. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Updated•5 months ago
|
Updated•4 months ago
|
| Assignee | ||
Comment 7•3 months ago
|
||
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/31709ebb8d58
NULL pointer dereference in CERT_MergeExtensions r=nss-reviewers,jschanck
Updated•3 months ago
|
Updated•2 months ago
|
Updated•2 months ago
|
Updated•13 days ago
|
Description
•