NSS 3.105 Release

"'Benjamin Beurdouche' via [email protected]" <[email protected]> Thu, 26 Sep 2024 18:35:12 +0200
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
--Apple-Mail=_9949F5E1-708B-470E-BADC-2C3168DE2A8B
Content-Type: text/plain; charset="UTF-8"

Dear all,

Network Security Services (NSS) 3.105 was tagged on 26th September 2024 and released today.

The HG tag is NSS_3_105_RTM. This version of NSS requires NSPR 4.35 or newer.

NSS 3.105 source distributions are available on ftp.mozilla.org <http://ftp.mozilla.org/> for
secure HTTPS download: https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_105_RTM/src/

Changes:

Bug 1915792 - Allow importing PKCS#8 private EC keys missing public key
Bug 1909768 - UBSAN fix: applying zero offset to null pointer in sslsnce.c
Bug 1919577 - set KRML_MUSTINLINE=inline in makefile builds
Bug 1918965 - Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys 
Bug 1918767 - override default definition of KRML_MUSTINLINE
Bug 1916525 - libssl support for mlkem768x25519
Bug 1916524 - support for ML-KEM-768 in softoken and pk11wrap
Bug 1866841 - Add Libcrux implementation of ML-KEM 768 to FreeBL
Bug 1911912 - Avoid misuse of ctype(3) functions
Bug 1917311 - part 2: run clang-format
Bug 1917311 - part 1: upgrade to clang-format 13
Bug 1916953 - clang-format fuzz
Bug 1910370 - DTLS client message buffer may not empty be on retransmit
Bug 1916413 - Optionally print config for TLS client and server fuzz target
Bug 1916059 - Fix some simple documentation issues in NSS.
Bug 1915439 - improve performance of NSC_FindObjectsInit when template has CKA_TOKEN attr
Bug 1912828 - define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN

NSS 3.105 shared libraries are backwards-compatible with all older NSS
3.x shared libraries. A program linked with older NSS 3.x shared
libraries will work with this new version of the shared libraries
without recompiling or relinking. Furthermore, applications that
restrict their use of NSS APIs to the functions listed in NSS Public
Functions will remain compatible with future versions of the NSS
shared libraries.

Bugs discovered should be reported by filing a bug report at
<https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS>

Release notes are available at
<https://firefox-source-docs.mozilla.org/security/nss/releases/index.html>.

Best,
Anna and Benjamin

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/2036A011-D03D-4B6B-86CC-AA098D509570%40mozilla.com.

--Apple-Mail=_9949F5E1-708B-470E-BADC-2C3168DE2A8B
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="UTF-8"

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=
=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; -webkit-nbsp-=
mode: space; line-break: after-white-space;"><div><div>Dear all,<br><br>Net=
work Security Services (NSS) 3.105 was tagged on 26th September 2024 and re=
leased today.<br><br>The HG tag is NSS_3_105_RTM. This version of NSS requi=
res NSPR 4.35 or newer.<br><br>NSS 3.105 source distributions are available=
 on&nbsp;<a href=3D"http://ftp.mozilla.org/" target=3D"_blank">ftp.mozilla.=
org</a>&nbsp;for<br>secure HTTPS download:&nbsp;<a href=3D"https://ftp.mozi=
lla.org/pub/security/nss/releases/NSS_3_105_RTM/src/">https://ftp.mozilla.o=
rg/pub/security/nss/releases/NSS_3_105_RTM/src/</a></div><div><br>Changes:<=
/div></div><div><br></div><div>Bug 1915792 - Allow importing PKCS#8 private=
 EC keys missing public key</div><div>Bug 1909768 - UBSAN fix: applying zer=
o offset to null pointer in sslsnce.c</div><div>Bug 1919577 - set KRML_MUST=
INLINE=3Dinline in makefile builds</div><div>Bug 1918965 - Don't set CKA_SI=
GN for CKK_EC_MONTGOMERY private keys&nbsp;</div><div>Bug 1918767 - overrid=
e default definition of KRML_MUSTINLINE</div><div>Bug 1916525 - libssl supp=
ort for mlkem768x25519</div><div>Bug 1916524 - support for ML-KEM-768 in so=
ftoken and pk11wrap</div><div>Bug 1866841 - Add Libcrux implementation of M=
L-KEM 768 to FreeBL</div><div>Bug 1911912 - Avoid misuse of ctype(3) functi=
ons</div><div>Bug 1917311 - part 2: run clang-format</div><div>Bug 1917311 =
- part 1: upgrade to clang-format 13</div><div>Bug 1916953 - clang-format f=
uzz</div><div>Bug 1910370 - DTLS client message buffer may not empty be on =
retransmit</div><div>Bug 1916413 - Optionally print config for TLS client a=
nd server fuzz target</div><div>Bug 1916059 - Fix some simple documentation=
 issues in NSS.</div><div>Bug 1915439 - improve performance of NSC_FindObje=
ctsInit when template has CKA_TOKEN attr</div><div>Bug 1912828 - define CKM=
_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN</div><div><br></div><div><div>NSS=
 3.105 shared libraries are backwards-compatible with all older NSS</div><d=
iv>3.x shared libraries. A program linked with older NSS 3.x shared</div><d=
iv>libraries will work with this new version of the shared libraries</div><=
div>without recompiling or relinking. Furthermore, applications that</div><=
div>restrict their use of NSS APIs to the functions listed in NSS Public</d=
iv><div>Functions will remain compatible with future versions of the NSS</d=
iv><div>shared libraries.</div><div><br></div><div>Bugs discovered should b=
e reported by filing a bug report at</div><div>&lt;https://bugzilla.mozilla=
.org/enter_bug.cgi?product=3DNSS&gt;</div><div><br></div><div>Release notes=
 are available at</div><div>&lt;https://firefox-source-docs.mozilla.org/sec=
urity/nss/releases/index.html&gt;.</div><div><br></div><div>Best,</div><div=
>Anna and Benjamin</div></div></body></html>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/mozilla.org/d/msgid/dev-tech-crypto/2036A011-D03D-4B6B-86CC-AA098D5095=
70%40mozilla.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.goo=
gle.com/a/mozilla.org/d/msgid/dev-tech-crypto/2036A011-D03D-4B6B-86CC-AA098=
D509570%40mozilla.com</a>.<br />

--Apple-Mail=_9949F5E1-708B-470E-BADC-2C3168DE2A8B--