{"id":"GHSA-g9mp-8g3h-3c5c","summary":"flynn/noise has improper nonce handling yielding potential state DoS","details":"The Go package `github.com/flynn/noise`, a [Noise Protocol](https://noiseprotocol.org/) implementation, has two bugs in nonce handling in versions prior to v1.0.0.\n\n### Issue 1: Potential nonce overflow\n\nIf 2\u003csup\u003e64\u003c/sup\u003e (~18.4 quintillion) or more messages are encrypted with `Encrypt` after handshaking, the nonce counter will wrap around, causing multiple messages to be encrypted with the same key and nonce, resulting in a potentially catastrophic weakening of the security properties of the symmetric cipher.\n\nThis has been resolved in the patched version by returning `ErrMaxNonce` from the `CipherState` `Encrypt` and `Decrypt` methods before the reserved maximum nonce is reached. If this error is encountered, the program should handshake again to start with a fresh `CipherState`.\n\n### Issue 2: Potential denial of service via invalid ciphertext\n\nIf an attacker sends an invalid ciphertext into one peer's `Decrypt`, the nonce is incremented unconditionally. This causes a desync of the `CipherState` due to a nonce mismatch between the peers, resulting in a failure to decrypt all subsequent messages. A new handshake will be required to establish a new `CipherState`.\n\nThis has been resolved in the patched version by returning authentication errors from `Decrypt` before incrementing the nonce. \n\n### Patches\n\nFixed in https://github.com/flynn/noise/pull/44, tagged as v1.0.0.\n\n### Acknowledgements\n\nThese issues were discovered during [an audit](https://www.bamsoftware.com/software/dnstt/cure53-turbotunnel-2021.pdf) of a user of this package ([dnstt](https://www.bamsoftware.com/software/dnstt/)). Thanks to UC Berkley for commissioning the audit, and to David Fifield and Nathan Brown for their collaboration on the fixes. The fixed issues are noted in the audit as:\n\n* UCB-02-003 Potential nonce overflow in Noise protocol\n* UCB-02-006 DoS due to unconditional nonce increment","aliases":["CVE-2021-4239","GHSA-6cr6-fmvc-vw2p","GO-2022-0425"],"modified":"2023-11-01T04:56:38.282458Z","published":"2022-02-15T01:57:18Z","database_specific":{"github_reviewed_at":"2021-05-18T21:46:19Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/flynn/noise/security/advisories/GHSA-g9mp-8g3h-3c5c"},{"type":"WEB","url":"https://github.com/flynn/noise/pull/44"},{"type":"PACKAGE","url":"https://github.com/flynn/noise"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-0425"}],"affected":[{"package":{"name":"github.com/flynn/noise","ecosystem":"Go","purl":"pkg:golang/github.com/flynn/noise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-g9mp-8g3h-3c5c/GHSA-g9mp-8g3h-3c5c.json"}}],"schema_version":"1.9.0"}