Allocation of Resources Without Limits or Throttling in Mozilla NSS - CVE-2020-25648
Published: October 21, 2020 / Updated: October 26, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
openEuler
Fedora
Red Hat OpenShift GitOps
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
Red Hat Advanced Cluster Management for Kubernetes
nss (Alpine package)
nss (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libnss3 (Ubuntu package)
nss-util
nss-util-devel
nss-debuginfo
nss-devel
nss-softokn
nss-help
nss-softokn-devel
nss-debugsource
nss
dev-libs/nss
nspr
nspr-devel
nspr (Red Hat package)
Oracle Communications Offline Mediation Controller
Oracle Communications Pricing Design Center
OpenShift Virtualization
How to mitigate CVE-2020-25648
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.3
nss (Red Hat package) - addressed in versions 3.53.1-7.el7_9, 3.67.0-6.el8_4
OpenShift Virtualization - addressed in versions 2.6.8, 4.9.0
libnss3 (Ubuntu package) - addressed in versions 2:3.35-2ubuntu2.14, 2:3.49.1-1ubuntu1.7
nss-util - update to 3.54.0-6
nss-util-devel - update to 3.54.0-6
nss-debuginfo - update to 3.54.0-6
nss-devel - update to 3.54.0-6
nss-softokn - update to 3.54.0-6
nss-help - update to 3.54.0-6
nss-softokn-devel - update to 3.54.0-6
nss-debugsource - update to 3.54.0-6
nss - update to 3.54.0-6
dev-libs/nss - update to 3.58
nss - addressed in versions 3.58.0-3.fc31, 3.58.0-3.fc32, 3.58.0-3.fc33
nspr - update to 4.32.0-1
nspr-devel - update to 4.32.0-1
nspr (Red Hat package) - update to 4.32.0-1.el8_4
External References
Related Security Bulletins
- Allocation of Resources Without Limits or Throttling in developer.mozilla nss
- Allocation of Resources Without Limits or Throttling in nss (Alpine package)
- Red Hat Enterprise Linux 7 update for nss
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Amazon Linux AMI update for nss
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Red Hat Enterprise Linux 8.4 update for nss and nspr
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Ubuntu update for nss
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Allocation of Resources Without Limits or Throttling in Oracle Communications Offline Mediation Controller
- Gentoo update for Mozilla Network Security Service (NSS)
- openEuler 20.03 LTS update for nss
- openEuler 20.03 LTS SP1 update for nss
- Anolis OS update for nspr
- Fedora 32 update for nss
- Fedora 33 update for nss
- Fedora 31 update for nss