NSS 3.122.1 Release
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <CAFgAd7ECRpu-z6K32PO2ZXWX_7h7wZRn2WaV0zJDp=A=v5jq6g@mail.gmail.com> |
--000000000000dda972064f604073 Content-Type: text/plain; charset="UTF-8" Network Security Services (NSS) 3.122.1 was released on 13 April 2026. The HG tag is NSS_3_122_1_RTM. This version of NSS requires NSPR 4.38 or newer. The latest version of NSPR is 4.38.2. NSS 3.122.1 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_122_1_RTM/src/> Changes: - Bug 2030135 - improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. - Bug 2029752 - Improving the allocation of S/MIME DecryptSymKey. - Bug 2029462 - store email on subject cache_entry in NSS trust domain. - Bug 2029425 - Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. - Bug 2029323 - Improve size calculations in CMS content buffering. - Bug 2028001 - avoid integer overflow while escaping RFC822 Names. - Bug 2027378 - Reject excessively large ASN.1 SEQUENCE OF in quickder. - Bug 2027365 - Deep copy profile data in CERT_FindSMimeProfile. - Bug 2027345 - Improve input validation in DSAU signature decoding. - Bug 2026311 - avoid integer overflow in RSA_EMSAEncodePSS. - Bug 2026156 - Add a maximum cert uncompressed len and tests. - Bug 2026089 - Clarify extension negotiation mechanism for TLS Handshakes. - Bug 1935995 - make ss->ssl3.hs.cookie an owned-copy of the cookie. -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAFgAd7ECRpu-z6K32PO2ZXWX_7h7wZRn2WaV0zJDp%3DA%3Dv5jq6g%40mail.gmail.com. --000000000000dda972064f604073 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Network Security Services (NSS) 3.122.1 was released on 13= April 2026.<br><br>The HG tag is NSS_3_122_1_RTM. This version of NSS requ= ires NSPR 4.38 or newer. The latest version of NSPR is 4.38.2.<br><br>NSS 3= .122.1 source distributions are available on <a href=3D"http://ftp.mozilla.= org">ftp.mozilla.org</a> for secure HTTPS download:<br><<a href=3D"https= ://ftp.mozilla.org/pub/security/nss/releases/NSS_3_122_1_RTM/src/">https://= ftp.mozilla.org/pub/security/nss/releases/NSS_3_122_1_RTM/src/</a>><br><= br>Changes:<br><br>=C2=A0 =C2=A0- Bug 2030135 - improve error handling in P= K11_ImportPrivateKeyInfoAndReturnKey.<br>=C2=A0 =C2=A0- Bug 2029752 - Impro= ving the allocation of S/MIME DecryptSymKey.<br>=C2=A0 =C2=A0- Bug 2029462 = - store email on subject cache_entry in NSS trust domain.<br>=C2=A0 =C2=A0-= Bug 2029425 - Heap use-after-free in cert_VerifyCertChainOld via dangling = certsList[] entry on NameConstraints violation.<br>=C2=A0 =C2=A0- Bug 20293= 23 - Improve size calculations in CMS content buffering.<br>=C2=A0 =C2=A0- = Bug 2028001 - avoid integer overflow while escaping RFC822 Names.<br>=C2=A0= =C2=A0- Bug 2027378 - Reject excessively large ASN.1 SEQUENCE OF in quickd= er.<br>=C2=A0 =C2=A0- Bug 2027365 - Deep copy profile data in CERT_FindSMim= eProfile.<br>=C2=A0 =C2=A0- Bug 2027345 - Improve input validation in DSAU = signature decoding.<br>=C2=A0 =C2=A0- Bug 2026311 - avoid integer overflow = in RSA_EMSAEncodePSS.<br>=C2=A0 =C2=A0- Bug 2026156 - Add a maximum cert un= compressed len and tests.<br>=C2=A0 =C2=A0- Bug 2026089 - Clarify extension= negotiation mechanism for TLS Handshakes.<br>=C2=A0 =C2=A0- Bug 1935995 - = make ss->ssl3.hs.cookie an owned-copy of the cookie.<br><br></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;[email protected]" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">dev-tech= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/mozill= a.org/d/msgid/dev-tech-crypto/CAFgAd7ECRpu-z6K32PO2ZXWX_7h7wZRn2WaV0zJDp%3D= A%3Dv5jq6g%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https:/= /groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAFgAd7ECRpu-z6K32= PO2ZXWX_7h7wZRn2WaV0zJDp%3DA%3Dv5jq6g%40mail.gmail.com</a>.<br /> --000000000000dda972064f604073--