Re: Freeze break request for NSS

"\"Douglas R. Reno\"" ([email protected] via blfs-dev Mailing List) <[email protected]> Mon, 16 Feb 2026 21:53:35 -0600
Newsgroups gmane.linux.lfs.beyond.devel
Message-ID <[email protected]>
On 2/16/26 4:24 PM, Bruce Dubbs ([email protected] via blfs-dev 
Mailing List) wrote:
> On 2/16/26 3:45 PM, "Douglas R. Reno" ([email protected] via 
> blfs-dev Mailing List) wrote:
>> Good afternoon,
>>
>> While I was poking around at Arch to figure something else out with 
>> valgrind, I noticed that they had a new version of NSS.
>>
>> It looks like NSS-3.120.1 was released on February 11th, but the 
>> currency scripts haven't picked up on it. It's available at it's 
>> normal location, and I'd like to request that it gets updated for 
>> BLFS 13.0 because of the following items in the release notes:
>>
>> "Bug 2009552 - avoid integer overflow in platform-independent ghash"
>>
>> Integer overflows can be exploited as a security vulnerability, and 
>> I'd thus like to request that it gets updated.
>>
>> Looking into the branch further, I noticed some additional commits 
>> that made it into this release but weren't listed in the release notes:
>>
>> "Bug 2008112 - Out-of-Bounds Read in ML-DSA Private Key Parsing 
>> (zero-length privateKey"
>>
>> "Bug 2007911 - FORWARD_NULL null deref of worker in p7decode.c 
>> (sec_pkcs7_decoder_abort_digests)"
>>
>> "Bug 2000737 - simplify compilation of platform-specific GCM and GHASH."
>>
>> "Bug 2000737 - rename C files for platform-specific ghash 
>> implementations."
>>
>> "Bug 2000737 - rename intel-{aes,gcm}.s to .S."
>>
>> "Bug 2000737 - Darwin compatibility for intel-aes.S and intel-gcm.S."
>>
>> "Bug 2001167: Paranoia assert."
>>
>> "Bug 2009998 - Update cryptofuzz version"
>>
>> "Bug 2005516 - allow manual selection of CPU_ARCH=x86_64 and ppc64 in 
>> coreconf/ Darwin.mk."
>>
>> "Bug 2010389 - Add e-Szigno TLS Root CA 2023 to NSS."
>>
>> "Bug 2010389 - Set nssckbi version to 2.84."
>>
>> "Bug 2013188 - add gcm.gyp dependency for Solaris SPARC builds."
>>
>> "Bug 2012313 - fix build with glibc-2.43 assignment discards 'const' 
>> qualifier from pointer."
>>
>> "Bug 2003189 - Fix errant whitespace in OISTE Server Root RSA G1 
>> nickname."
>>
>>
>> The log for this version can be found at 
>> https://hg-edge.mozilla.org/projects/nss/ 
>> log/80e5c1939f9babba274362f9efbf3db87391ce64 - you'll need to click 
>> on -20 is required if you want to see when 3.120.0 was tagged.
>>
>> Note that this includes a root certificate update as well based on 
>> the above information. I did look and there doesn't seem to be any 
>> API changes that would be problematic for us here, they are mostly 
>> bugfixes (and the C files for platform specific ghash implementations 
>> are internal). There's also a glibc build fix here but I don't think 
>> we were ever affected by it since the package is currently tagged.
>
> Go ahead and update nss but recheck p11-kit and mand-ca.
>
>   -- Bruce
>
I just updated NSS to 3.120.1 in 
57fa92771d34e25bf3cea0c1f320c0ddb7280fb1 and everything is looking good 
with the tests, as well as make-ca and p11-kit :)

- Doug

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page