Re: Freeze break request for NSS
"\"Douglas R. Reno\"" ([email protected] via blfs-dev Mailing List) <[email protected]> Mon, 16 Feb 2026 21:53:35 -0600
| Newsgroups | gmane.linux.lfs.beyond.devel |
|---|---|
| Message-ID | <[email protected]> |
On 2/16/26 4:24 PM, Bruce Dubbs ([email protected] via blfs-dev Mailing List) wrote: > On 2/16/26 3:45 PM, "Douglas R. Reno" ([email protected] via > blfs-dev Mailing List) wrote: >> Good afternoon, >> >> While I was poking around at Arch to figure something else out with >> valgrind, I noticed that they had a new version of NSS. >> >> It looks like NSS-3.120.1 was released on February 11th, but the >> currency scripts haven't picked up on it. It's available at it's >> normal location, and I'd like to request that it gets updated for >> BLFS 13.0 because of the following items in the release notes: >> >> "Bug 2009552 - avoid integer overflow in platform-independent ghash" >> >> Integer overflows can be exploited as a security vulnerability, and >> I'd thus like to request that it gets updated. >> >> Looking into the branch further, I noticed some additional commits >> that made it into this release but weren't listed in the release notes: >> >> "Bug 2008112 - Out-of-Bounds Read in ML-DSA Private Key Parsing >> (zero-length privateKey" >> >> "Bug 2007911 - FORWARD_NULL null deref of worker in p7decode.c >> (sec_pkcs7_decoder_abort_digests)" >> >> "Bug 2000737 - simplify compilation of platform-specific GCM and GHASH." >> >> "Bug 2000737 - rename C files for platform-specific ghash >> implementations." >> >> "Bug 2000737 - rename intel-{aes,gcm}.s to .S." >> >> "Bug 2000737 - Darwin compatibility for intel-aes.S and intel-gcm.S." >> >> "Bug 2001167: Paranoia assert." >> >> "Bug 2009998 - Update cryptofuzz version" >> >> "Bug 2005516 - allow manual selection of CPU_ARCH=x86_64 and ppc64 in >> coreconf/ Darwin.mk." >> >> "Bug 2010389 - Add e-Szigno TLS Root CA 2023 to NSS." >> >> "Bug 2010389 - Set nssckbi version to 2.84." >> >> "Bug 2013188 - add gcm.gyp dependency for Solaris SPARC builds." >> >> "Bug 2012313 - fix build with glibc-2.43 assignment discards 'const' >> qualifier from pointer." >> >> "Bug 2003189 - Fix errant whitespace in OISTE Server Root RSA G1 >> nickname." >> >> >> The log for this version can be found at >> https://hg-edge.mozilla.org/projects/nss/ >> log/80e5c1939f9babba274362f9efbf3db87391ce64 - you'll need to click >> on -20 is required if you want to see when 3.120.0 was tagged. >> >> Note that this includes a root certificate update as well based on >> the above information. I did look and there doesn't seem to be any >> API changes that would be problematic for us here, they are mostly >> bugfixes (and the C files for platform specific ghash implementations >> are internal). There's also a glibc build fix here but I don't think >> we were ever affected by it since the package is currently tagged. > > Go ahead and update nss but recheck p11-kit and mand-ca. > > -- Bruce > I just updated NSS to 3.120.1 in 57fa92771d34e25bf3cea0c1f320c0ddb7280fb1 and everything is looking good with the tests, as well as make-ca and p11-kit :) - Doug -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page