Re: Freeze break request for NSS
"Bruce Dubbs" ([email protected] via blfs-dev Mailing List) <[email protected]> Mon, 16 Feb 2026 16:24:04 -0600
| Newsgroups | gmane.linux.lfs.beyond.devel |
|---|---|
| Message-ID | <[email protected]> |
On 2/16/26 3:45 PM, "Douglas R. Reno" ([email protected] via blfs-dev Mailing List) wrote: > Good afternoon, > > While I was poking around at Arch to figure something else out with valgrind, I > noticed that they had a new version of NSS. > > It looks like NSS-3.120.1 was released on February 11th, but the currency scripts > haven't picked up on it. It's available at it's normal location, and I'd like to > request that it gets updated for BLFS 13.0 because of the following items in the > release notes: > > "Bug 2009552 - avoid integer overflow in platform-independent ghash" > > Integer overflows can be exploited as a security vulnerability, and I'd thus like to > request that it gets updated. > > Looking into the branch further, I noticed some additional commits that made it into > this release but weren't listed in the release notes: > > "Bug 2008112 - Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey" > > "Bug 2007911 - FORWARD_NULL null deref of worker in p7decode.c > (sec_pkcs7_decoder_abort_digests)" > > "Bug 2000737 - simplify compilation of platform-specific GCM and GHASH." > > "Bug 2000737 - rename C files for platform-specific ghash implementations." > > "Bug 2000737 - rename intel-{aes,gcm}.s to .S." > > "Bug 2000737 - Darwin compatibility for intel-aes.S and intel-gcm.S." > > "Bug 2001167: Paranoia assert." > > "Bug 2009998 - Update cryptofuzz version" > > "Bug 2005516 - allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/ > Darwin.mk." > > "Bug 2010389 - Add e-Szigno TLS Root CA 2023 to NSS." > > "Bug 2010389 - Set nssckbi version to 2.84." > > "Bug 2013188 - add gcm.gyp dependency for Solaris SPARC builds." > > "Bug 2012313 - fix build with glibc-2.43 assignment discards 'const' qualifier from > pointer." > > "Bug 2003189 - Fix errant whitespace in OISTE Server Root RSA G1 nickname." > > > The log for this version can be found at https://hg-edge.mozilla.org/projects/nss/ > log/80e5c1939f9babba274362f9efbf3db87391ce64 - you'll need to click on -20 is > required if you want to see when 3.120.0 was tagged. > > Note that this includes a root certificate update as well based on the above > information. I did look and there doesn't seem to be any API changes that would be > problematic for us here, they are mostly bugfixes (and the C files for platform > specific ghash implementations are internal). There's also a glibc build fix here but > I don't think we were ever affected by it since the package is currently tagged. Go ahead and update nss but recheck p11-kit and mand-ca. -- Bruce -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page