SUSE-RU-2026:23851-1: moderate: Recommended update for mozilla-nss

SLE-UPDATES null at suse.de
Thu Sep 24 20:44:32 UTC 2026


# Recommended update for mozilla-nss

Announcement ID: SUSE-RU-2026:23851-1  
Release Date: 2026-09-21T09:30:24Z  
Rating: moderate  
References:

  * bsc#1262698
  * bsc#1266262
  * bsc#1279863

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that has three fixes can now be installed.

## Recommended update for mozilla-nss

### Description:

This update for mozilla-nss fixes the following issues:

Changes in mozilla-nss:

  * Fix potential crash when verifying password length in PBKDF2 (boo#1279863)
  * Fix upper bound to allow FIPS approval for P-521.
  * Approve HKDF and key concatenation in the context of TLS. This enables
    approved TLS 1.3 channels with PQC (bsc#1262698).
  * Don't consider unapproved algorithms for TLS 1.3 in FIPS mode.
  * Mark TLS 1.2 KDF without extended master secret non-approved for FIPS
    (bsc#1266262).

## Recommended update for mozilla-nss

### Description:

This update for mozilla-nss fixes the following issues:

Changes in mozilla-nss:

  * Fix potential crash when verifying password length in PBKDF2 (boo#1279863)
  * Fix upper bound to allow FIPS approval for P-521.
  * Approve HKDF and key concatenation in the context of TLS. This enables
    approved TLS 1.3 channels with PQC (bsc#1262698).
  * Don't consider unapproved algorithms for TLS 1.3 in FIPS mode.
  * Mark TLS 1.2 KDF without extended master secret non-approved for FIPS
    (bsc#1266262).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1722

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1722

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * mozilla-nss-sysinit-debuginfo-3.125-160000.2.1
    * libfreebl3-3.125-160000.2.1
    * mozilla-nss-3.125-160000.2.1
    * libfreebl3-debuginfo-3.125-160000.2.1
    * libsoftokn3-3.125-160000.2.1
    * mozilla-nss-debugsource-3.125-160000.2.1
    * mozilla-nss-tools-3.125-160000.2.1
    * libsoftokn3-debuginfo-3.125-160000.2.1
    * mozilla-nss-certs-debuginfo-3.125-160000.2.1
    * mozilla-nss-devel-3.125-160000.2.1
    * mozilla-nss-debuginfo-3.125-160000.2.1
    * mozilla-nss-tools-debuginfo-3.125-160000.2.1
    * mozilla-nss-certs-3.125-160000.2.1
    * mozilla-nss-sysinit-3.125-160000.2.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
    * mozilla-nss-sysinit-debuginfo-3.125-160000.2.1
    * libfreebl3-3.125-160000.2.1
    * mozilla-nss-3.125-160000.2.1
    * libfreebl3-debuginfo-3.125-160000.2.1
    * libsoftokn3-3.125-160000.2.1
    * mozilla-nss-debugsource-3.125-160000.2.1
    * mozilla-nss-tools-3.125-160000.2.1
    * libsoftokn3-debuginfo-3.125-160000.2.1
    * mozilla-nss-certs-debuginfo-3.125-160000.2.1
    * mozilla-nss-devel-3.125-160000.2.1
    * mozilla-nss-debuginfo-3.125-160000.2.1
    * mozilla-nss-tools-debuginfo-3.125-160000.2.1
    * mozilla-nss-certs-3.125-160000.2.1
    * mozilla-nss-sysinit-3.125-160000.2.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1262698
  * https://bugzilla.suse.com/show_bug.cgi?id=1266262
  * https://bugzilla.suse.com/show_bug.cgi?id=1279863

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260924/c75d4970/attachment.htm>


More information about the sle-updates mailing list