NSS 3.103 release
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <CAMeH0+osuA9u0CauzNYRengUTCU1z_oaMNwL2Aw8EEx7PTh7Ew@mail.gmail.com> |
--000000000000fbf7bd061ef1f7b1 Content-Type: text/plain; charset="UTF-8" Dear all, Network Security Services (NSS) 3.103 was released on 1st August 2024. The HG tag is NSS_3_103_RTM. This version of NSS requires NSPR 4.35 or newer. NSS 3.103 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_103_RTM/src/> Changes: - Bug 1908623 - move list size check after lock acquisition in sftk_PutObjectToList. - Bug 1899542 - Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH. - Bug 1909638 - Follow-up to fix test for presence of file nspr.patch. - Bug 1903783 - Adjust libFuzzer size limits. - Bug 1899542 - Add fuzzing support for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk. - Bug 1899542 - Add fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTATION. - Bug 1909638 - NSS automation should always cleanup the NSPR tree. - Bug 590806 - Freeing symKey in pk11_PubDeriveECKeyWithKDF when a key_size is 0 and wrong kd. - Bug 1908831 - Don't link zlib where it's not needed. - Bug 1908597 - Removing dead code from X25519 seckey. - Bug 1905691 - ChaChaXor to return after the functio. - Bug 1900416 - NSS Support of X25519 import/export functionalit. - Bug 1890618 - add PeerCertificateChainDER function to libssl. - Bug 1908190 - fix definitions of freeblCipher_native_aes_*_worker on arm. - Bug 1907743 - pk11mode: avoid passing null phKey to C_DeriveKey. - Bug 1902119 - reuse X25519 share when offering both X25519 and Xyber768d00. - Set nssckbi version number to 2.69. - Bug 1904404 - add NSS_DISABLE_NSPR_TESTS option to makefile. - Bug 1905746 - avoid calling functions through pointers of incompatible type. - Bug 1905783 - merge docker-fuzz32 and docker-fuzz images. - Bug 1903373 - fix several scan-build warnings. NSS 3.103 shared libraries are backwards-compatible with all older NSS 3.x shared libraries. A program linked with older NSS 3.x shared libraries will work with this new version of the shared libraries without recompiling or relinking. Furthermore, applications that restrict their use of NSS APIs to the functions listed in NSS Public Functions will remain compatible with future versions of the NSS shared libraries. Bugs discovered should be reported by filing a bug report at <https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS> Release notes are available at <https://firefox-source-docs.mozilla.org/security/nss/releases/index.html>. Best, Anna -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2BosuA9u0CauzNYRengUTCU1z_oaMNwL2Aw8EEx7PTh7Ew%40mail.gmail.com. --000000000000fbf7bd061ef1f7b1 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Dear all,<br>Network Security Services (NSS) 3.103 was rel= eased on 1st August 2024.<br><br>The HG tag is NSS_3_103_RTM. This version = of NSS requires NSPR<br>4.35 or newer.<br><br>NSS 3.103 source distribution= s are available on <a href=3D"http://ftp.mozilla.org">ftp.mozilla.org</a><b= r>for secure HTTPS download:<br><<a href=3D"https://ftp.mozilla.org/pub/= security/nss/releases/NSS_3_103_RTM/src/">https://ftp.mozilla.org/pub/secur= ity/nss/releases/NSS_3_103_RTM/src/</a>><br><br>Changes:<br>=C2=A0 =C2= =A0- Bug 1908623 - move list size check after lock acquisition in sftk_PutO= bjectToList.<br>=C2=A0 =C2=A0- Bug 1899542 - Add fuzzing support for SSL_EN= ABLE_POST_HANDSHAKE_AUTH.<br>=C2=A0 =C2=A0- Bug 1909638 - Follow-up to fix = test for presence of file nspr.patch.<br>=C2=A0 =C2=A0- Bug 1903783 - Adjus= t libFuzzer size limits.<br>=C2=A0 =C2=A0- Bug 1899542 - Add fuzzing suppor= t for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_= VersionRangeSet and SSL_AddExternalPsk.<br>=C2=A0 =C2=A0- Bug 1899542 - Add= fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTAT= ION.<br>=C2=A0 =C2=A0- Bug 1909638 - NSS automation should always cleanup t= he NSPR tree.<br>=C2=A0 =C2=A0- Bug 590806 - Freeing symKey in pk11_PubDeri= veECKeyWithKDF when a key_size is 0 and wrong kd.<br>=C2=A0 =C2=A0- Bug 190= 8831 - Don't link zlib where it's not needed.<br>=C2=A0 =C2=A0- Bug= 1908597 - Removing dead code from X25519 seckey.<br>=C2=A0 =C2=A0- Bug 190= 5691 - ChaChaXor to return after the functio.<br>=C2=A0 =C2=A0- Bug 1900416= - NSS Support of X25519 import/export functionalit.<br>=C2=A0 =C2=A0- Bug = 1890618 - add PeerCertificateChainDER function to libssl.<br>=C2=A0 =C2=A0-= Bug 1908190 - fix definitions of freeblCipher_native_aes_*_worker on arm.<= br>=C2=A0 =C2=A0- Bug 1907743 - pk11mode: avoid passing null phKey to C_Der= iveKey.<br>=C2=A0 =C2=A0- Bug 1902119 - reuse X25519 share when offering bo= th X25519 and Xyber768d00.<br>=C2=A0 =C2=A0- Set nssckbi version number to = 2.69.<br>=C2=A0 =C2=A0- Bug 1904404 - add NSS_DISABLE_NSPR_TESTS option to = makefile.<br>=C2=A0 =C2=A0- Bug 1905746 - avoid calling functions through p= ointers of incompatible type.<br>=C2=A0 =C2=A0- Bug 1905783 - merge docker-= fuzz32 and docker-fuzz images.<br>=C2=A0 =C2=A0- Bug 1903373 - fix several = scan-build warnings.<br><br>NSS 3.103 shared libraries are backwards-compat= ible with all<br>older NSS 3.x shared libraries. A program linked with olde= r NSS<br>3.x shared libraries will work with this new version of the<br>sha= red libraries without recompiling or relinking. Furthermore,<br>application= s that restrict their use of NSS APIs to the<br>functions listed in NSS Pub= lic Functions will remain compatible<br>with future versions of the NSS sha= red libraries.<br><br>Bugs discovered should be reported by filing a bug re= port at<br><<a href=3D"https://bugzilla.mozilla.org/enter_bug.cgi?produc= t=3DNSS">https://bugzilla.mozilla.org/enter_bug.cgi?product=3DNSS</a>><b= r><br>Release notes are available at<br><<a href=3D"https://firefox-sour= ce-docs.mozilla.org/security/nss/releases/index.html">https://firefox-sourc= e-docs.mozilla.org/security/nss/releases/index.html</a>>.<br><br>Best,<b= r>Anna<br></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;[email protected]" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">dev-tech= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2BosuA9u0CauzNYRengUTCU1z_o= aMNwL2Aw8EEx7PTh7Ew%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter= ">https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2B= osuA9u0CauzNYRengUTCU1z_oaMNwL2Aw8EEx7PTh7Ew%40mail.gmail.com</a>.<br /> --000000000000fbf7bd061ef1f7b1--