Low firefox Logic Error

Overview

Low
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
Impactlow
Description<code>NSC_DeriveKey</code> inadvertently assumed that the <code>phKey</code> parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows <code>phKey</code> to be NULL for certain mechanisms.
ComponentCore
Bug ClassLogic Error
Tracker1921768
CISA KEVNot listed
Creditedcoffeys
Disclosed2024-11-26

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.
On This Page