CVE-2024-36121 - CVE House
Back to Database
Status published Medium CVE-2024-36121

netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces

Vulnerability Description

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker to cause the sequence number to overflow and thus the nonce to repeat.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-36121

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

netty-incubator-codec-ohttp
Vulnerable Versions:
>= 0.0.3.Final, < 0.0.11.Final

Timeline

Official Publish: June 4th, 2024
Last Modified: August 6th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N