NSS 3.112.4 Release

"'John Schanck' via [email protected]" <[email protected]> Mon, 13 Apr 2026 16:57:38 -0700
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAFgAd7FGXtSNXXST9Lxq7gVhNLrbdAfOG+0juB8p+eDmBo9+tQ@mail.gmail.com>
--000000000000f0f1c6064f604026
Content-Type: text/plain; charset="UTF-8"

Network Security Services (NSS) 3.112.4 was released on 13 April 2026.

The HG tag is NSS_3_112_4_RTM. This version of NSS requires NSPR 4.36 or
newer. The latest version of NSPR is 4.38.2.

NSS 3.112.4 source distributions are available on ftp.mozilla.org for
secure HTTPS download:
<https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_112_4_RTM/src/>

Changes:

   -  Bug 2030135 - improve error handling in
PK11_ImportPrivateKeyInfoAndReturnKey.
   -  Bug 2029752 - Improving the allocation of S/MIME DecryptSymKey.
   -  Bug 2029462 - store email on subject cache_entry in NSS trust domain.
   -  Bug 2029425 - Heap use-after-free in cert_VerifyCertChainOld via
dangling certsList[] entry on NameConstraints violation.
   -  Bug 2029323 - Improve size calculations in CMS content buffering.
   -  Bug 2028001 - avoid integer overflow while escaping RFC822 Names.
   -  Bug 2027378 - Reject excessively large ASN.1 SEQUENCE OF in quickder.
   -  Bug 2027365 - Deep copy profile data in CERT_FindSMimeProfile.
   -  Bug 2027345 - Improve input validation in DSAU signature decoding.
   -  Bug 2026311 - avoid integer overflow in RSA_EMSAEncodePSS.
   -  Bug 2019357 - RSA_EMSAEncodePSS should validate the length of mHash.
   -  Bug 2026156 - Add a maximum cert uncompressed len and tests.
   -  Bug 2026089 - Clarify extension negotiation mechanism for TLS
Handshakes.
   -  Bug 2023209 - ensure permittedSubtrees don't match wildcards that
could be outside the permitted tree.
   -  Bug 2023207 - Fix integer underflow in tls13_AEAD when ciphertext is
shorter than tag.
   -  Bug 2019224 - Remove invalid PORT_Free().
   -  Bug 1964722 - free digest objects in SEC_PKCS7DecoderFinish if they
haven't already been freed.
   -  Bug 1935995 - make ss->ssl3.hs.cookie an owned-copy of the cookie.

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAFgAd7FGXtSNXXST9Lxq7gVhNLrbdAfOG%2B0juB8p%2BeDmBo9%2BtQ%40mail.gmail.com.

--000000000000f0f1c6064f604026
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Network Security Services (NSS) 3.112.4 was released on 13=
 April 2026.<br><br>The HG tag is NSS_3_112_4_RTM. This version of NSS requ=
ires NSPR 4.36 or newer. The latest version of NSPR is 4.38.2.<br><br>NSS 3=
.112.4 source distributions are available on <a href=3D"http://ftp.mozilla.=
org">ftp.mozilla.org</a> for secure HTTPS download:<br>&lt;<a href=3D"https=
://ftp.mozilla.org/pub/security/nss/releases/NSS_3_112_4_RTM/src/">https://=
ftp.mozilla.org/pub/security/nss/releases/NSS_3_112_4_RTM/src/</a>&gt;<br><=
br>Changes:<br><br>=C2=A0 =C2=A0- =C2=A0Bug 2030135 - improve error handlin=
g in PK11_ImportPrivateKeyInfoAndReturnKey.<br>=C2=A0 =C2=A0- =C2=A0Bug 202=
9752 - Improving the allocation of S/MIME DecryptSymKey.<br>=C2=A0 =C2=A0- =
=C2=A0Bug 2029462 - store email on subject cache_entry in NSS trust domain.=
<br>=C2=A0 =C2=A0- =C2=A0Bug 2029425 - Heap use-after-free in cert_VerifyCe=
rtChainOld via dangling certsList[] entry on NameConstraints violation.<br>=
=C2=A0 =C2=A0- =C2=A0Bug 2029323 - Improve size calculations in CMS content=
 buffering.<br>=C2=A0 =C2=A0- =C2=A0Bug 2028001 - avoid integer overflow wh=
ile escaping RFC822 Names.<br>=C2=A0 =C2=A0- =C2=A0Bug 2027378 - Reject exc=
essively large ASN.1 SEQUENCE OF in quickder.<br>=C2=A0 =C2=A0- =C2=A0Bug 2=
027365 - Deep copy profile data in CERT_FindSMimeProfile.<br>=C2=A0 =C2=A0-=
 =C2=A0Bug 2027345 - Improve input validation in DSAU signature decoding.<b=
r>=C2=A0 =C2=A0- =C2=A0Bug 2026311 - avoid integer overflow in RSA_EMSAEnco=
dePSS.<br>=C2=A0 =C2=A0- =C2=A0Bug 2019357 - RSA_EMSAEncodePSS should valid=
ate the length of mHash.<br>=C2=A0 =C2=A0- =C2=A0Bug 2026156 - Add a maximu=
m cert uncompressed len and tests.<br>=C2=A0 =C2=A0- =C2=A0Bug 2026089 - Cl=
arify extension negotiation mechanism for TLS Handshakes.<br>=C2=A0 =C2=A0-=
 =C2=A0Bug 2023209 - ensure permittedSubtrees don&#39;t match wildcards tha=
t could be outside the permitted tree.<br>=C2=A0 =C2=A0- =C2=A0Bug 2023207 =
- Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag.<=
br>=C2=A0 =C2=A0- =C2=A0Bug 2019224 - Remove invalid PORT_Free().<br>=C2=A0=
 =C2=A0- =C2=A0Bug 1964722 - free digest objects in SEC_PKCS7DecoderFinish =
if they haven&#39;t already been freed.<br>=C2=A0 =C2=A0- =C2=A0Bug 1935995=
 - make ss-&gt;ssl3.hs.cookie an owned-copy of the cookie.<br><br><br><br><=
/div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/mozill=
a.org/d/msgid/dev-tech-crypto/CAFgAd7FGXtSNXXST9Lxq7gVhNLrbdAfOG%2B0juB8p%2=
BeDmBo9%2BtQ%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https=
://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAFgAd7FGXtSNXXS=
T9Lxq7gVhNLrbdAfOG%2B0juB8p%2BeDmBo9%2BtQ%40mail.gmail.com</a>.<br />

--000000000000f0f1c6064f604026--