SUSE-SU-2026:23411-1: critical: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen
SLE-UPDATES
null at suse.de
Wed Sep 2 12:31:31 UTC 2026
# Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen
Announcement ID: SUSE-SU-2026:23411-1
Release Date: 2026-08-31T15:29:17Z
Rating: critical
References:
* bsc#1262698
* bsc#1262701
* bsc#1266262
* bsc#1266263
* bsc#1271649
* bsc#1272772
* bsc#1272773
* bsc#1272774
* bsc#1274867
Cross-References:
* CVE-2026-16349
* CVE-2026-16350
* CVE-2026-16351
* CVE-2026-16352
* CVE-2026-16353
* CVE-2026-16354
* CVE-2026-16355
* CVE-2026-16356
* CVE-2026-16357
* CVE-2026-16358
* CVE-2026-16359
* CVE-2026-16360
* CVE-2026-16362
* CVE-2026-16363
* CVE-2026-16364
* CVE-2026-16365
* CVE-2026-16366
* CVE-2026-16367
* CVE-2026-16368
* CVE-2026-16369
* CVE-2026-16370
* CVE-2026-16371
* CVE-2026-16372
* CVE-2026-16373
* CVE-2026-16374
* CVE-2026-16375
* CVE-2026-16376
* CVE-2026-16377
* CVE-2026-16378
* CVE-2026-16379
* CVE-2026-16380
* CVE-2026-16381
* CVE-2026-16382
* CVE-2026-16383
* CVE-2026-16384
* CVE-2026-16385
* CVE-2026-16386
* CVE-2026-16387
* CVE-2026-16388
* CVE-2026-16389
* CVE-2026-16390
* CVE-2026-16391
* CVE-2026-16392
* CVE-2026-16393
* CVE-2026-16394
* CVE-2026-16395
* CVE-2026-16396
* CVE-2026-16397
* CVE-2026-16398
* CVE-2026-16399
* CVE-2026-16400
* CVE-2026-16401
* CVE-2026-16402
* CVE-2026-16403
* CVE-2026-16404
* CVE-2026-16405
* CVE-2026-16406
* CVE-2026-16407
* CVE-2026-16408
* CVE-2026-16409
* CVE-2026-16410
* CVE-2026-16411
* CVE-2026-16412
* CVE-2026-74934
* CVE-2026-74935
* CVE-2026-74936
* CVE-2026-74937
* CVE-2026-74938
* CVE-2026-74939
* CVE-2026-74940
* CVE-2026-74941
* CVE-2026-74942
* CVE-2026-74943
* CVE-2026-74944
* CVE-2026-74945
* CVE-2026-74946
* CVE-2026-74947
* CVE-2026-74948
* CVE-2026-74949
* CVE-2026-74950
* CVE-2026-74953
* CVE-2026-74954
* CVE-2026-74955
* CVE-2026-74956
* CVE-2026-74957
* CVE-2026-74958
* CVE-2026-74959
* CVE-2026-74960
* CVE-2026-74961
* CVE-2026-74962
* CVE-2026-74963
* CVE-2026-74964
* CVE-2026-74965
* CVE-2026-74966
* CVE-2026-74967
* CVE-2026-74968
* CVE-2026-74969
* CVE-2026-74970
* CVE-2026-74971
* CVE-2026-74972
* CVE-2026-74973
* CVE-2026-74974
* CVE-2026-74976
* CVE-2026-74977
* CVE-2026-74978
* CVE-2026-74979
* CVE-2026-74981
* CVE-2026-74982
* CVE-2026-74983
* CVE-2026-74984
* CVE-2026-74985
* CVE-2026-74986
* CVE-2026-74987
* CVE-2026-74988
* CVE-2026-74990
CVSS scores:
* CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
* CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16397 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-16404 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
* CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Micro 6.2
An update that solves 115 vulnerabilities can now be installed.
## Description:
This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes
the following issues:
Changes in MozillaFirefox:
Firefox Extended Support Release 153.1.0 ESR.
* Fixed: Various security fixes.
MFSA 2026-77 (bsc#1274867):
* CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component
* CVE-2026-74935 Privilege escalation in the DOM: Networking component
* CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-74937 Use-after-free in the JavaScript: GC component
* CVE-2026-74938 Mitigation bypass in the JavaScript: GC component
* CVE-2026-74939 Privilege escalation in the DOM: Navigation component
* CVE-2026-74940 Use-after-free in the Graphics: Text component
* CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component
* CVE-2026-74942 Privilege escalation in the Remote Settings Client component
* CVE-2026-74943 Use-after-free in the Graphics: ImageLib component
* CVE-2026-74944 Use-after-free in the DOM: Core & HTML component
* CVE-2026-74945 Information disclosure in the Graphics: Text component
* CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in
the Graphics: CanvasWebGL component
* CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics
component
* CVE-2026-74948 Information disclosure in the Graphics component
* CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics:
Canvas2D component
* CVE-2026-74950 Privilege escalation in the Downloads API component
* CVE-2026-74953 Privilege escalation in the Networking: Cookies component
* CVE-2026-74954 Information disclosure due to side-channel in the Storage:
Cache API component
* CVE-2026-74955 Privilege escalation in the Request Handling component
* CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers
component
* CVE-2026-74957 Mitigation bypass in the Safe Browsing component
* CVE-2026-74958 Information disclosure in the WebRTC component
* CVE-2026-74959 Mitigation bypass in the Storage: Cache API component
* CVE-2026-74960 Site isolation issue in the WebExtensions component
* CVE-2026-74961 Side-channel in the Web Audio component
* CVE-2026-74962 Site isolation issue in the Networking: Cookies component
* CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies
component
* CVE-2026-74964 Integer overflow in the Graphics component
* CVE-2026-74965 Privilege escalation in the Shell Integration component
* CVE-2026-74966 Information disclosure in the Form Autofill component
* CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback
component
* CVE-2026-74968 Site isolation issue in the Graphics: WebRender component
* CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component
* CVE-2026-74970 Site isolation issue in the Graphics component
* CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling
component
* CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions
component
* CVE-2026-74973 Race condition, use-after-free in the Graphics component
* CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component
* CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-74977 Integer overflow in the Graphics component
* CVE-2026-74978 Clickjacking issue in the Widget component
* CVE-2026-74979 Mitigation bypass in the Add-ons Manager component
* CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component
* CVE-2026-74982 Denial-of-service in the Widget component
* CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component
* CVE-2026-74984 Race condition in the JavaScript Engine component
* CVE-2026-74985 Privilege escalation in the Enterprise Policies component
* CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation
component
* CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox
ESR 153.1 and Firefox 154
* CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox
154
* CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox
ESR 140.14, Firefox ESR 153.1 and Firefox 154
Firefox Extended Support Release 153.0esr ESR
* New: ## General
* Firefox now includes a new profile management system that helps you separate
your online life into distinct profiles for work, school, vacation planning,
or whatever you choose. Profiles can be customized with names, avatars, and
color themes while keeping tabs, bookmarks, passwords, and browsing history
separate. Built-in profile backup and restore also makes it easier to
migrate to a new device or recover your browsing data.
* Split View lets you view two webpages side-by-side in a single browser
window, with additional options to quickly open links in Split View,
rearrange pages, and search open tabs.
* The Firefox address bar has gained several new capabilities, including
built-in unit and time zone conversion, quick actions such as muting all
browser audio, and direct search results as you type.
* Firefox now supports copying links directly to highlighted text on a webpage
for easier sharing.
* Firefox Settings has been redesigned with improved organization and
navigation, making it easier to find and customize browser preferences.
* New: ## AI
Firefox introduced several new AI-powered features, including on-device tab
organization, AI-assisted link previews, integrated AI search, and centralized
controls for managing AI features. Whenever possible, these features perform
processing locally to help protect user privacy.
* New: ## Sidebar and Tabs
* Firefox continues to improve tab management with enhancements to vertical
tabs, tab groups, and the sidebar.
* Tab groups have gained numerous usability improvements, including better
support for collapsed groups, previews of grouped tabs, and additional
organization options.
* Passwords can now be accessed directly from the Firefox sidebar without
opening a separate tab.
* Firefox now supports copying links from one or multiple background tabs
directly from the tab context menu, and multiple tabs can be copied or
shared in a single action.
* A Send Tab toolbar button is now available through Customize Toolbar.
* New: ## Security & Privacy
* Firefox has significantly expanded Fingerprinting Protection, making it
harder for websites to uniquely identify users in both Standard and Strict
Enhanced Tracking Protection modes.
* Enhanced Tracking Protection includes stronger protections against bounce
tracking and additional safeguards that restrict websites from accessing
local network resources without user permission.
* Firefox now uses Safe Browsing V5 for phishing and malware protection.
* Firefox Password Manager now uses stronger AES-256 encryption to protect
stored logins on disk.
* Private Browsing has been enhanced with new controls, including the ability
to instantly end a private browsing session and temporarily relax tracker
blocking for individual sites when needed for compatibility.
* New: ## Translations
* Firefox has expanded on-device translation support with many additional
languages and continued improvements to translation quality.
* A dedicated translations page now provides an easy way to perform real-time
translations directly within Firefox.
* New: ## Accessibility
* Firefox continues to improve accessibility with enhanced support for
assistive technologies, including Windows UI Automation, improved keyboard
navigation, more accessible date and time controls, and better support for
mathematical content in PDFs.
* New: ## Linux
* Firefox now supports native fractional scaling on Wayland, improving
rendering on high-DPI displays.
* Firefox no longer requires a restart after package manager updates and uses
less memory on Linux.
* Firefox now supports the XDG Base Directory Specification and ships with RPM
packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions.
* HTML5: - Firefox now supports the View Transitions API for creating smooth
animated transitions between application views.
* WebGPU support has expanded across supported platforms, including Windows
and Apple Silicon Macs.
* Added support for several modern web platform APIs, improving compatibility
with modern web applications. Notable additions include the Navigation API,
URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling.
* Enterprise: - Enterprise administrators can now centrally manage Firefox's
Generative AI features through enterprise policy.
* Fixed a performance regression affecting native messaging, improving
responsiveness for enterprise extensions that communicate with external
applications.
* Enterprise policy documentation has moved to https://firefox-admin-
docs.mozilla.org/.
* Fixed: Various security fixes.
* MFSA 2026-68 (bsc#1271649):
* CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component
* CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb
component
* CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component
* CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation
component
* CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access
APIs component
* CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
* CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback
component
* CVE-2026-16365 Privilege escalation in the DOM: Workers component
* CVE-2026-16366 Privilege escalation in the DOM: Navigation component
* CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component
* CVE-2026-16354 Information disclosure in the Graphics: ImageLib component
* CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability
Access APIs component
* CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly
component
* CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component
* CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access
APIs component
* CVE-2026-16357 Incorrect boundary conditions in the Graphics component
* CVE-2026-16370 Mitigation bypass in the DOM: Networking component
* CVE-2026-16371 Privilege escalation in the DOM: Navigation component
* CVE-2026-16372 Privilege escalation in the DOM: Content Processes component
* CVE-2026-16373 Information disclosure in the Privacy component in Firefox
for Android
* CVE-2026-16374 Information disclosure in the Framework component in DevTools
* CVE-2026-16375 Site isolation issue in the Networking: HTTP component
* CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component
* CVE-2026-16377 Mitigation bypass in the PDF Viewer component
* CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop
component
* CVE-2026-16379 Privilege escalation in the DOM: Content Processes component
* CVE-2026-16358 Site isolation issue in the Graphics: WebRender component
* CVE-2026-16380 Mitigation bypass in the Networking component
* CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component
* CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16383 Mitigation bypass in the DOM: Networking component
* CVE-2026-16384 Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
* CVE-2026-16385 Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
* CVE-2026-16386 Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
* CVE-2026-16387 Site isolation issue in the Networking component
* CVE-2026-16388 Sandbox escape in the DOM: Networking component
* CVE-2026-16389 Incorrect boundary conditions, integer overflow in the
Libraries component in NSS
* CVE-2026-16390 Mitigation bypass in the Enterprise Policies component
* CVE-2026-16391 Information disclosure in the Storage: IndexedDB component
* CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU
component
* CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP
component
* CVE-2026-16394 Mitigation bypass in the DOM: Security component
* CVE-2026-16395 Integer overflow in the Audio/Video component
* CVE-2026-16396 Privilege escalation in WebExtensions
* CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox
for Android
* CVE-2026-16398 Site isolation issue in the Graphics component
* CVE-2026-16399 Site isolation issue in the DOM: Navigation component
* CVE-2026-16400 Information disclosure in the DOM: Security component
* CVE-2026-16401 Privilege escalation in the Data Loss Prevention component
* CVE-2026-16402 Integer overflow in the Graphics: ImageLib component
* CVE-2026-16403 Spoofing issue in the Address Bar component
* CVE-2026-16404 Spoofing issue in Firefox for Android
* CVE-2026-16405 Information disclosure in the Networking: WebSockets
component
* CVE-2026-16406 Mitigation bypass in the Networking component
* CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16408 Integer overflow in the Audio/Video: Playback component
* CVE-2026-16409 Invalid pointer in the Security: PSM component
* CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16411 Memory safety bugs fixed in Firefox 153
* CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox
153
* CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
140.13 and Firefox 153
Changes in mozilla-nss:
* Add patch to prefer any hybrid PQC and send at most one hybrid key share
(bsc#1262698).
* Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263).
* Import ML-DSA implementation and related PQC fixes from upstream
(bsc#1262698, bsc#1272772).
* Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773).
* Add zeroization for ML-KEM, ported from upstream (bsc#1272774).
* Add zeroization for ML-DSA (bsc#1272774).
* Add ML-DSA robustness and test fixes.
* Add PQC algorithms to approved list. Increase approved symmetric keygen
floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms
(bsc#1266262).
update to NSS 3.125
* Set nssckbi version to 2.88.
* Add Cybertrust Japan SecureSign Root CA16.
* Remove Email Trust bit from TrustAsia Global Root CA G3 and G4.
* Remove Entrust Root Certification Authority.
* Remove SecureSign Root CA12.
* Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket.
* replace references to nss-dev/nss with mozilla/nss.
* limit recursion depth in CMS decoder.
* clamp input.len to testString size in pk11_mergeSecretKey.
* NULL pointer dereference in CERT_MergeExtensions.
* CERT_DecodeAVAValue — Integer Overflow in Output Buffer Sizing.
* fix two integer overflows on LLP64 systems.
* Modify an assertion in ssl3_ClientSendAppProtoXtn.
* Import RSA-PSS PKCS#8 private keys.
* Update fuzz/config/tstclnt_arguments.py.
* Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey.
* Adding a guard against integer overflow in AESKeyWrap_EncryptKWP.
* Add an integer overflow guard in UpdateBase64Decoder.
* Void out the fd.release in reconfig tests.
* make sftk_FindAttribute return a copy.
* Converted nss parameter schema from voluptuous to msgspec.
* drop slot monitor in PK11_ResetToken before calling PK11_InitToken.
* adjust the code to use nspr from github.
* avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword.
* test pk11auth.c functions with a non-threadsafe module.
* PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor.
* reject empty nickname in PK11_TraverseCertsForNicknameInSlot.
* validate encoded EC params length and tag in
SECKEY_ECParamsToKeySize/BasePointOrderLen.
* guard space subtraction in ssl_CallCustomExtensionSenders.
* rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned
overflow.
* bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity.
* Set tail pointer to null in static slot lists when deallocating.
* avoid leaving a dangling ss->sec.ci.sid on allocation failure.
* guard against integer overflow in CERT_Hexify.
* Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1].
* NUL-terminate within filename field in jar_listtar to bound the filename
scan.
* Widen CERT_FormatName length accumulator from unsigned to size_t.
* Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation.
* Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of
asserting.
* Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans
bounded.
* Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End.
* Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes.
* Guard padding read against empty output in SEC_PKCS7DecryptContents.
* Guard against keySize overflow in IKE PRF/PRF+ output sizing.
* Allocate values array when overwriting an empty CMS attribute.
* Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute.
* Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib.
* Handle zero-length input in PrepareBitStringForEncoding.
* Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in
JAR_parse_manifest.
* Reject CKA_NSS_MODULE_SPEC values that aren’t NUL-terminated within
ulValueLen.
* Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7.
* Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b.
* doc: import NSS:TryServer wiki page in the tree.
* improve PK11 URI tests.
* avoid nested attributeLock acquisition in sftk_CopyObject.
* doc: fix a typo in “Community — Network Security Services (NSS)”.
* acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair.
* Reject empty nickname in PK11_TraverseCertsForNicknameInSlot.
* require non-null session pointer in sftk_GetContext.
* set session->lastOpWasFIPS while holding session reference.
* atomically claim object removal in sftk_DeleteObject.
* atomically swap session search in NSC_FindObjects*.
* atomically install session contexts in C_*Init.
* hold session reference for context lifetime in C_*Update.
* align softoken session lock with head-bucket hash.
* restore reference counting for SFTKSession.
* update to NSS 3.124
* Add test for PKCS7 digest array alignment
* Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder
* Add test for CMS content size validation
* Add regression tests for DSAU signature decoding
* Add test for S/MIME profile lookup on temp certs
* Test case for post-handshake auth and many certificate requests
* Add test for intra-arena ASan redzones
* update nss_status flags one at a time
* add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR
* avoid PORT_Strdup in ssl_DecodeResumptionToken
* add runtime check on decoded resumption token session id
* improve mach try error handling
* clang format
* add comprehensive SECItem and SECItemArray tests
* add bugzilla_cf_status_nss.py script
* regenerate some recent release notes
* fix bug list output by release note and email scripts
* test removal from trust domain email cache
* fix "testing if key corruption is detected in attribute" failures with
sqlite-3.53.0
* build sqlite3 shell for Windows CI runners
* avoid race with module unloading in NSSTrustDomain_FindTokensByURI
* add ImportEd25519WithNonEmptyAlgorithmParams test
* add CLAUDE.md and .mcp.json
* add a mach try command
* remove dead condition in sec_asn1d_check_and_subtract_length
* avoid integer truncation in nssCKObject_GetAttributes
* add defensive input validation to sftk_compute_ANSI_X9_63_kdf
* avoid refcount over-release in nssTokenObjectCache error path [@
nssToken_Destroy]
* sdb: enforce that metaData's id key is unique when reading
* improve handling of escape sequences in pk11uri_ParseAttributes
* use correct data for ID comparison in transfer_uri_certs_to_collection
* fix truncation of ulValueLen in sdb_FindObjectsInit
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
* set previous-nss-release for abicheck
* Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData`
* consistently protect PK11SlotInfo::maxKeyCount with freeListLock
* Remove CRMF from testing and manifests
* Remove unused RSA blind signature implementation from freebl
* update to NSS 3.123.1
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
* update to NSS 3.123
* https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o
* update to NSS 3.122.2:
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
* update to NSS 3.122.1
* improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey.
* Improving the allocation of S/MIME DecryptSymKey.
* store email on subject cache_entry in NSS trust domain.
* Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[]
entry on NameConstraints violation.
* Improve size calculations in CMS content buffering.
* avoid integer overflow while escaping RFC822 Names.
* Reject excessively large ASN.1 SEQUENCE OF in quickder.
* Deep copy profile data in CERT_FindSMimeProfile.
* Improve input validation in DSAU signature decoding.
* avoid integer overflow in RSA_EMSAEncodePSS.
* Add a maximum cert uncompressed len and tests.
* Clarify extension negotiation mechanism for TLS Handshakes.
* make ss->ssl3.hs.cookie an owned-copy of the cookie.
* update to NSS 3.122
* ensure permittedSubtrees don't match wildcards that could be outside the
permitted tree.
* run mach doc-lint from generate_release_doc.py.
* Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag.
* tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable.
* fix cipher spec count intermittent CI failures.
* fix Mlkem768x25519ShareDamager intermittent CI failures.
* lint the legacy documentation.
* lint the NSS 3.112.3 release notes.
* add a doc-lint CI job.
* Add more useful coverage reports to CI and fail if new commit isn't tested.
* wrong alert for malformed TLS 1.3 Finished.
* Swap order of asserts and state check.
* set correct value of unused curve parameters in tls13_HandleKeyShare.
* GCM needs to check for various limits in FIPS mode.
* Get Key Length not working from ED and Montgomery keys.
* Not all ike modes are FIPS approved. Adjust the indicators when they aren't.
* fix intermittent ssl.sh test failures on windows runners.
* FIPS indicators on HKDF needs to be restricted to TLS usage.
* Generate keys not getting indicators.
* improve error handling in smime_init_once.
* Detect CPU features on OpenBSD using elf_aux_info.
* RSA_EMSAEncodePSS should validate the length of mHash.
* more robustly distinguish SFTKSessionObject and SFTKTokenObjects.
* fix missing .S file error in Solaris Makefile builds.
* fix memory leak in NSC_GenerateKey error path.
* Missing SECFailure return after FATAL_ERROR in
tls13_HandleEncryptedExtensions.
* release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths.
* release 1stHandshakeLock on SSL_ResetHandshake error path.
* avoid null deref in mp_div_d sign normalization.
* Temp private key lifecycle is broken.
* protect rwSessionCount with slotLock.
* Remove invalid PORT_Free().
* Fix intermittent ClientGreaseKeyShare test failure.
* Fix kCtxStr len passed to tls_SignOrVerifyUpdate.
* patch upstream acvp-rust during checkout to avoid build failures.
* update acvp Dockerfile.
* CKA_PARAM_SET missing from the CK_ULONG list in softoken.
* CKA_SEED missing from isPrivate in the database.
* update abicheck expectation for __nss_InitLock.
* taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds.
* tests: fix setup_policy to use ROOTCERTSFILE for root cert module path.
* tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT.
* tests: add native_path helper for cross-platform path conversion.
* tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows.
* avoid platform GCM for x64 iOS emulator builds.
* remove lock instrumentation feature.
* Move FIPS indicator structures out of fips_algorithms.h.
* all.sh is failing in FIPS SSL test in main tree.
* fix memory leaks in crmf tests.
* fix unsatisfiable condition in lg_getTrust.
* allow selfserv makefile build to use system zlib.
* Add allocation limit to pkcs12 decoding.
* Add text/html single-line example emails to NSS S/SMIME CMS tests.
* update to NSS 3.121
* update vendored zlib to v1.3.2.
* Revert the unnecessary changes to intel-gcm-wrap.gyp.
* Use C fallback for AES-GCM on MinGW builds.
* fix ML-KEM PCT.
* Extend NSS Fuzzing docs.
* avoid integer overflow in platform-independent ghash.
* Fix errant whitespace in OISTE Server Root RSA G1 nickname.
* add gcm.gyp dependency for Solaris SPARC builds.
* Set nssckbi version to 2.84.
* Add e-Szigno TLS Root CA 2023 to NSS.
* allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk.
* Update cryptofuzz version.
* Paranoia assert.
* Darwin compatibility for intel-aes.S and intel-gcm.S.
* rename intel-{aes,gcm}.s to .S.
* rename C files for platform-specific ghash implementations.
* simplify compilation of platform-specific GCM and GHASH.
* FORWARD_NULL null deref of worker in p7decode.c
(sec_pkcs7_decoder_abort_digests).
* Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey).
* update to NSS 3.120.1
* no upstream releasenotes
* update to NSS 3.120
* Fix docs generation bug.
* CID 1678226: Dereferencing null pointer plaintext.data().
* Run PKCS12 fuzz target with --fuzz=tls in CI.
* Allowing RT be started several times.
* move linux decision and build tasks to d2g worker pools.
* update to NSS 3.119.1
* restore coreconf/Darwin.mk behavior for intel archs
* update to NSS 3.119
* Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits.
* Make sure we don't accept ECH if the HRR cookie is ill-formatted.
* Add a pkcs12 fuzzer with crypto stubbed out.
* handle errors while setting sanitizers cflags in build.
* Ignore IVs for AES KW.
* Update Cryptofuzz version.
* Fix incorrect logic for SNI selection when ECH is available but disabled.
* fix forwarding of sqlite_libs in sqlite.gyp.
* fix CPU_ARCH setting for arm64 makefile builds.
* remove unused calcThreads variable from cmd/rsaperf.
* Solving the incorrect tests introduced by extending EKU.
* Memory leaks in pkcs12 and pkcs7 decoders.
* Extending parsing with Microsoft Document Signing EKU.
* Extending parsing with Adobe Document Signing EKU.
* Extending pkix parsing with document signing EKUs.
* fix compilation failure on ia32.
* use hardware x64 GCM in static builds.
* separate ppc sha512 library from ppc gcm library.
* simplify cross-compilation from build.sh.
* use clang's integrated assembler.
* remove unused MP_IS_LITTLE_ENDIAN defines.
* fix logic for disabling altivec in gyp builds.
* free digest objects in SEC_PKCS7DecoderFinish if they haven't already been
freed.
* Add TLS interoperability tests with openssl and gnutls.
* Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest.
* add failure checks to pk11_mergeTrust() .
* pk11wrap selects incorrect slot for CKM_ML_KEM*.
* Adjusted for changed naming scheme of tarballs for this release by upstream
* update to NSS 3.118.1
* pk11wrap selects incorrect slot for CKM_ML_KEM*
* update to NSS 3.118
* Remove four Commscope root certificates from NSS
* fix try pushes with --nspr-patch to actually apply the patch
* Support for NIST Curves compressed points
* Destroy certificate on error paths
* Move NSS DB password hash away from SHA-1
* support secp384r1mlkem1024
* vendor latest ML-KEM code from libcrux
* add mlk-kem-1024 tests
* use the correct directory for FStar_UInt_8_16_32_64.h in source consistency
test
* Move scripts to python3
* add mlkem1024 support in freebl
* support secp256r1mlkem768
* Make mlkem768x25519 the default
* ML-DSA SGN and VFY interfaces
* Align FIPS interfaces count with array
* Ensure CKK_ML_KEM has derive CK_FALSE
* Add script for tagging an NSS release
* Remove the globals from nss-release-helper.py
* Add release helper command for generating the release index
* Add release helper command for generating a release note
* Add release helper command for freezing a branch
* update to NSS 3.117
* fix memory leak in secasn1decode_unittest.cc
* Add OISTE roots
* Add runbook for certdata.txt changes
* dbtool: close databases before shutdown
* SEC_ASN1Decode* should ensure it has read as many bytes as each length field
indicates
* don’t flush base64 when buffer is null
* Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds
* mozilla::pkix: recognize the qcStatements extension for QWACs
* Fix a big-endian-problematic cast in zlib calls
* Revert removing out/ directory after ossfuzz build
* Add Cryptofuzz to OSS-Fuzz build
* Add PKCS#11 trust tests
* final disable dsa patch cert.sh
* ml-dsa: move tls 1.3 to use streaming signatures
* ml-dsa: Prep Create a FindOidTagByString function
* ml-dsa: softoken changes
* ml-dsa: der key decode
* ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi
* ml-dsa: Prep Create a CreateSignatureAlgorithmID function
* update to NSS 3.116
* disable DSA in NSS script tests
* Disabling of some algorithms: generic cert.sh
* Need to update to new mechanisms
* Add ML-DSA public key printing support in NSS command-line utilities
* note embedded scts before revocation checks are performed
* Add support for ML-DSA keys and mechanisms in PKCS#11 interface
* Add support for ML-DSA key type and public key structure
* Enable ML-DSA integration via OIDs support and SECMOD flag
* disable kyber
* Implement PKCS #11 v3.2 PQ functions (use verify signature)
* Disable dsa - gtests
* make group and scheme support in test tools generic
* Create GH workflow to automatically close PRs
* Disable dsa - base code
* Disabling of some algorithms: remove dsa from pk11_mode
* Disable seed and RC2 bug fixes
* restore support for finding certificates by decoded serial number
* avoid CKR_BUFFER_TO_SMALL error in trust lookups
* lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type
* Use PKCS #11 v3.2 KEM mechanisms and functions
* update to NSS 3.115.1
* restore support for finding certificates by decoded serial number.
* avoid CKR_BUFFER_TO_SMALL error in trust lookups.
* update to NSS 3.115
* CID 1648399 - Resource leak in shlibsign.c
* CKA_SEED needs to be marked as a private attribute
* Fix bad syntax on Windows in softoken_gtest.cc
* Key private/public/secret keys by key type in softoken keydb
* add PK11_HPKE_GetSharedSecret to abi-check expected report
* remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain
* Fixup ABI
* add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server
* ECH fuzz target
* Implement PKCS #11 v3.2 FIPS indicator and validation objects
* remove expired explicitly distrusted DigiNotar lookalike root
* Implement PKCS #11 v3.2 functions
* update to NSS 3.114
* NSS 3.114 source distribution should include NSPR 4.37
* Prevent leaks during pkcs12 decoding
* Remove redundant assert in p7local.c
* Bump nssckbi version to 2.80
* Remove expired Baltimore CyberTrust Root
* Add TrustAsia Dedicated Roots to NSS
* Add SwissSign 2022 Roots to NSS
* Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS
* Implement PKCS #11 v3.2 trust objects in softoken
* Implement PKCS #11 v3.2 trust objects - nss proper
* remove dead code in ssl3con.c
* DTLS (excl DTLS1.3) Changing Holddown timer logic
* Bump nssckbi version to 2.79
* remove unneccessary assertion
* Update mechanisms for Softoken PCT
* convert Chunghwa Telecom ePKI Root removal to a distrust after
* Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks
* use -O2 for asan build
* Fix leaking locks when toggling SSL_NO_LOCKS
* remove out-of-function semicolon
* Extend pkcs8 fuzz target
* Extend pkcs7 fuzz target
* Remove unused assignment to pageno
* Remove unused assignment to nextChunk
* don't run commands as part of shell `local` declarations
* fix sanitizer setup
* don't silence ssl_gtests output when running with coverage
* Release docs and housekeeping
* migrate to new linux tester pool
* update to NSS 3.113
* Fix alias for mac workers on try.
* Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea
* Bump nssckbi version to 2.78.
* Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141.
* fix frame pointers in intel-gcm.s.
* Typo in release notes for NSS 101.4.
* Improve nss-release-helper.py.
* shlibsign is broken in System FIPS mode.
* Need up update NSS for PKCS 3.1: Move IPSEC to 3.1
* PKCS #11 v3.2 header files.
Changes in mozilla-nspr:
* update to NSPR 4.39
* Improved error handling in PR_CreateThread on Windows
* Cleanup and Type-cast fixes for prtime
* Remove unused prstreams C++ wrapper from NSPR
* Memory poisoning and Arena redzone fixes
* Removed emacs/vim modelines and .cvsignore files
* Added .editorconfig
* update to version 4.38.2
* Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1
* update to version 4.38.1
* Incorrect time value produced by PR_ParseTimeString and
PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds.
* update to version 4.38
* Removed support for HPUX and _PR_POLL_WITH_SELECT
* Fixed a bug in pt_TCP_SendTo on macOS
* Ensure parameter passed to isalpha() is unsigned char
* update to version 4.37
* PR_GetUniqueIdentity asserts on the 32767th call
* error LNK2019: unresolved external symbol _InterlockedCompareExchange
* initclk deadline elapsed macOS
* Remove prwin.h (formerly known as prwin16.h)
* Use builtin atomic functions on RISC-V32/64
* PR_FormatTimeUSEnglish() doesn't support "%e" format specifier
Changes in rust-cbindgen:
* Update to version v0.29.4+git0:
* tests: Add some tests for constant enums.
* ir: Add support for arrays.
* ir: Allow constant literals with enum variants.
* ir: Use Path for ConstExprs.
* tests: Fix tests with modern gcc.
* Use C++ fixed-type enumeration syntax under C23 (or higher) as well
* Allow `pub` access to `ReprType` fields
* Update to version 0.29.2+git0:
* Check for CMSE ABI's as well
* Fix doc attribute parsing to properly handle block comments
* Expose the line_endings config option to use with the builder
* Explicitly request serde's std features to avoid issues with newer toml
versions.
* enum: Track dependencies properly in enumerations.
* Update to version 0.29.2+git0:
* Explicitly request serde's std features to avoid issues with newer toml
versions.
* Account for master -> main rename.
* Update changelog and bump version.
* enum: Track dependencies properly in enumerations.
* Allow must_use if a reason is specified
* constant: Handle cfg in associated constants.
* tests: Add a test for bitflags + disjoint cfg.
* Remove "display" feature from the toml crate
* DOC: Add metatensor
* Fix #1085 - Incorrect detection of duplicated constants
* chore: More clippy fixes.
* docs: Correct after_include type in example config
* cargo update
* cfg: Remove another clippy warning.
* Fix `clippy::uninlined_format_args`
* Update toml to 0.9
* Release 0.29.0
* Support no-export annotation for statics and functions.
* conditional fields of constexpr literal structs
* Add LiteralStructField
* Github action: Add aarch64 to deploy
* Add rename rule for generated associated constant
* Upgrade heck to 0.5
* Add support for an optional nullable attribute
* docs.md: Fix deprecated_with_note and deprecated_variant_with_note being
spelled as 'notes'
* Fix generic with "void" default
* The return of Cast is simplified
* Added tests for as keyword inside array into structs
* Fixed error generation of structures using the keyword of as inside arrays
* Added test for unsafe(no_mangle) attribute
* Added tests for unsafe methotd's atributs
* Fixed handling of trait methods containing the unsafe attribute
* Rename -Zparse-only
* tests: Fix symbol file and tests.
* tests: Run rustfmt.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Micro 6.2
zypper in -t patch SUSE-SL-Micro-6.2-1570=1
## Package List:
* SUSE Linux Micro 6.2 (aarch64 ppc64le x86_64)
* libfreebl3-debuginfo-3.125-160000.1.1
* mozilla-nss-tools-3.125-160000.1.1
* libfreebl3-3.125-160000.1.1
* mozilla-nss-tools-debuginfo-3.125-160000.1.1
* mozilla-nspr-4.39-160000.1.1
* libsoftokn3-debuginfo-3.125-160000.1.1
* libsoftokn3-3.125-160000.1.1
* mozilla-nspr-debuginfo-4.39-160000.1.1
* mozilla-nss-certs-3.125-160000.1.1
* mozilla-nspr-debugsource-4.39-160000.1.1
* mozilla-nss-debugsource-3.125-160000.1.1
* mozilla-nss-3.125-160000.1.1
* mozilla-nss-debuginfo-3.125-160000.1.1
* mozilla-nss-certs-debuginfo-3.125-160000.1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16349.html
* https://www.suse.com/security/cve/CVE-2026-16350.html
* https://www.suse.com/security/cve/CVE-2026-16351.html
* https://www.suse.com/security/cve/CVE-2026-16352.html
* https://www.suse.com/security/cve/CVE-2026-16353.html
* https://www.suse.com/security/cve/CVE-2026-16354.html
* https://www.suse.com/security/cve/CVE-2026-16355.html
* https://www.suse.com/security/cve/CVE-2026-16356.html
* https://www.suse.com/security/cve/CVE-2026-16357.html
* https://www.suse.com/security/cve/CVE-2026-16358.html
* https://www.suse.com/security/cve/CVE-2026-16359.html
* https://www.suse.com/security/cve/CVE-2026-16360.html
* https://www.suse.com/security/cve/CVE-2026-16362.html
* https://www.suse.com/security/cve/CVE-2026-16363.html
* https://www.suse.com/security/cve/CVE-2026-16364.html
* https://www.suse.com/security/cve/CVE-2026-16365.html
* https://www.suse.com/security/cve/CVE-2026-16366.html
* https://www.suse.com/security/cve/CVE-2026-16367.html
* https://www.suse.com/security/cve/CVE-2026-16368.html
* https://www.suse.com/security/cve/CVE-2026-16369.html
* https://www.suse.com/security/cve/CVE-2026-16370.html
* https://www.suse.com/security/cve/CVE-2026-16371.html
* https://www.suse.com/security/cve/CVE-2026-16372.html
* https://www.suse.com/security/cve/CVE-2026-16373.html
* https://www.suse.com/security/cve/CVE-2026-16374.html
* https://www.suse.com/security/cve/CVE-2026-16375.html
* https://www.suse.com/security/cve/CVE-2026-16376.html
* https://www.suse.com/security/cve/CVE-2026-16377.html
* https://www.suse.com/security/cve/CVE-2026-16378.html
* https://www.suse.com/security/cve/CVE-2026-16379.html
* https://www.suse.com/security/cve/CVE-2026-16380.html
* https://www.suse.com/security/cve/CVE-2026-16381.html
* https://www.suse.com/security/cve/CVE-2026-16382.html
* https://www.suse.com/security/cve/CVE-2026-16383.html
* https://www.suse.com/security/cve/CVE-2026-16384.html
* https://www.suse.com/security/cve/CVE-2026-16385.html
* https://www.suse.com/security/cve/CVE-2026-16386.html
* https://www.suse.com/security/cve/CVE-2026-16387.html
* https://www.suse.com/security/cve/CVE-2026-16388.html
* https://www.suse.com/security/cve/CVE-2026-16389.html
* https://www.suse.com/security/cve/CVE-2026-16390.html
* https://www.suse.com/security/cve/CVE-2026-16391.html
* https://www.suse.com/security/cve/CVE-2026-16392.html
* https://www.suse.com/security/cve/CVE-2026-16393.html
* https://www.suse.com/security/cve/CVE-2026-16394.html
* https://www.suse.com/security/cve/CVE-2026-16395.html
* https://www.suse.com/security/cve/CVE-2026-16396.html
* https://www.suse.com/security/cve/CVE-2026-16397.html
* https://www.suse.com/security/cve/CVE-2026-16398.html
* https://www.suse.com/security/cve/CVE-2026-16399.html
* https://www.suse.com/security/cve/CVE-2026-16400.html
* https://www.suse.com/security/cve/CVE-2026-16401.html
* https://www.suse.com/security/cve/CVE-2026-16402.html
* https://www.suse.com/security/cve/CVE-2026-16403.html
* https://www.suse.com/security/cve/CVE-2026-16404.html
* https://www.suse.com/security/cve/CVE-2026-16405.html
* https://www.suse.com/security/cve/CVE-2026-16406.html
* https://www.suse.com/security/cve/CVE-2026-16407.html
* https://www.suse.com/security/cve/CVE-2026-16408.html
* https://www.suse.com/security/cve/CVE-2026-16409.html
* https://www.suse.com/security/cve/CVE-2026-16410.html
* https://www.suse.com/security/cve/CVE-2026-16411.html
* https://www.suse.com/security/cve/CVE-2026-16412.html
* https://www.suse.com/security/cve/CVE-2026-74934.html
* https://www.suse.com/security/cve/CVE-2026-74935.html
* https://www.suse.com/security/cve/CVE-2026-74936.html
* https://www.suse.com/security/cve/CVE-2026-74937.html
* https://www.suse.com/security/cve/CVE-2026-74938.html
* https://www.suse.com/security/cve/CVE-2026-74939.html
* https://www.suse.com/security/cve/CVE-2026-74940.html
* https://www.suse.com/security/cve/CVE-2026-74941.html
* https://www.suse.com/security/cve/CVE-2026-74942.html
* https://www.suse.com/security/cve/CVE-2026-74943.html
* https://www.suse.com/security/cve/CVE-2026-74944.html
* https://www.suse.com/security/cve/CVE-2026-74945.html
* https://www.suse.com/security/cve/CVE-2026-74946.html
* https://www.suse.com/security/cve/CVE-2026-74947.html
* https://www.suse.com/security/cve/CVE-2026-74948.html
* https://www.suse.com/security/cve/CVE-2026-74949.html
* https://www.suse.com/security/cve/CVE-2026-74950.html
* https://www.suse.com/security/cve/CVE-2026-74953.html
* https://www.suse.com/security/cve/CVE-2026-74954.html
* https://www.suse.com/security/cve/CVE-2026-74955.html
* https://www.suse.com/security/cve/CVE-2026-74956.html
* https://www.suse.com/security/cve/CVE-2026-74957.html
* https://www.suse.com/security/cve/CVE-2026-74958.html
* https://www.suse.com/security/cve/CVE-2026-74959.html
* https://www.suse.com/security/cve/CVE-2026-74960.html
* https://www.suse.com/security/cve/CVE-2026-74961.html
* https://www.suse.com/security/cve/CVE-2026-74962.html
* https://www.suse.com/security/cve/CVE-2026-74963.html
* https://www.suse.com/security/cve/CVE-2026-74964.html
* https://www.suse.com/security/cve/CVE-2026-74965.html
* https://www.suse.com/security/cve/CVE-2026-74966.html
* https://www.suse.com/security/cve/CVE-2026-74967.html
* https://www.suse.com/security/cve/CVE-2026-74968.html
* https://www.suse.com/security/cve/CVE-2026-74969.html
* https://www.suse.com/security/cve/CVE-2026-74970.html
* https://www.suse.com/security/cve/CVE-2026-74971.html
* https://www.suse.com/security/cve/CVE-2026-74972.html
* https://www.suse.com/security/cve/CVE-2026-74973.html
* https://www.suse.com/security/cve/CVE-2026-74974.html
* https://www.suse.com/security/cve/CVE-2026-74976.html
* https://www.suse.com/security/cve/CVE-2026-74977.html
* https://www.suse.com/security/cve/CVE-2026-74978.html
* https://www.suse.com/security/cve/CVE-2026-74979.html
* https://www.suse.com/security/cve/CVE-2026-74981.html
* https://www.suse.com/security/cve/CVE-2026-74982.html
* https://www.suse.com/security/cve/CVE-2026-74983.html
* https://www.suse.com/security/cve/CVE-2026-74984.html
* https://www.suse.com/security/cve/CVE-2026-74985.html
* https://www.suse.com/security/cve/CVE-2026-74986.html
* https://www.suse.com/security/cve/CVE-2026-74987.html
* https://www.suse.com/security/cve/CVE-2026-74988.html
* https://www.suse.com/security/cve/CVE-2026-74990.html
* https://bugzilla.suse.com/show_bug.cgi?id=1262698
* https://bugzilla.suse.com/show_bug.cgi?id=1262701
* https://bugzilla.suse.com/show_bug.cgi?id=1266262
* https://bugzilla.suse.com/show_bug.cgi?id=1266263
* https://bugzilla.suse.com/show_bug.cgi?id=1271649
* https://bugzilla.suse.com/show_bug.cgi?id=1272772
* https://bugzilla.suse.com/show_bug.cgi?id=1272773
* https://bugzilla.suse.com/show_bug.cgi?id=1272774
* https://bugzilla.suse.com/show_bug.cgi?id=1274867
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260902/f3cf8243/attachment-0001.htm>
More information about the sle-updates
mailing list