🛡️ SUSE-RU-2024:2564-1 — mozilla-nss (CVE-2023-5388)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Recommended update for mozilla-nss

This update for mozilla-nss fixes the following issues:

  • Fixed startup crash of Firefox when using FIPS-mode (bsc#1223724).
  • Added 'Provides: nss' so other RPMs that require 'nss' can

be installed (jira PED-6358).

  • FIPS: added safe memsets (bsc#1222811)
  • FIPS: restrict AES-GCM (bsc#1222830)
  • FIPS: Updated FIPS approved cipher lists (bsc#1222813, bsc#1222814, bsc#1222821, bsc#1222822, bsc#1224118)
  • FIPS: Updated FIPS self tests (bsc#1222807, bsc#1222828, bsc#1222834)
  • FIPS: Updated FIPS approved cipher lists (bsc#1222804, bsc#1222826, bsc#1222833, bsc#1224113, bsc#1224115, bsc#1224116)

update to NSS 3.101.1:

  • GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.

update to NSS 3.101:

  • add diagnostic assertions for SFTKObject refcount.
  • freeing the slot in DeleteCertAndKey if authentication failed
  • fix formatting issues.
  • Add Firmaprofesional CA Root-A Web to NSS.
  • remove invalid acvp fuzz test vectors.
  • pad short P-384 and P-521 signatures gtests.
  • remove unused FreeBL ECC code.
  • pad short P-384 and P-521 signatures.
  • be less strict about ECDSA private key length.
  • Integrate HACL* P-521.
  • Integrate HACL* P-384.
  • memory leak in create_objects_from_handles.
  • ensure all input is consumed in a few places in mozilla::pkix
  • SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
  • clean up escape handling
  • Use lib::pkix as default validator instead of the old-one
  • Need to add high level support for PQ signing.
  • Certificate Compression: changing the allocation/freeing of buffer + Improving the documentation
  • SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
  • Allow for non-full length ecdsa signature when using softoken
  • Modification of .taskcluster.yml due to mozlint indent defects
  • Implement support for PBMAC1 in PKCS#12
  • disable VLA warnings for fuzz builds.
  • remove redundant AllocItem implementation.
  • add PK11_ReadDistrustAfterAttribute.
  • - Clang-formatting of SEC_GetMgfTypeByOidTag update
  • Set SEC_ERROR_LIBRARY_FAILURE on self-test failure
  • sftk_getParameters(): Fix fallback to default variable after error with configfile.
  • Switch to the mozillareleases/image_builder image
  • switch from ec_field_GFp to ec_field_plain

Update to NSS 3.100:

  • merge pk11_kyberSlotList into pk11_ecSlotList for faster Xyber operations.
  • remove ckcapi.
  • avoid a potential PK11GenericObject memory leak.
  • Remove incomplete ESDH code.
  • Decrypt RSA OAEP encrypted messages.
  • Fix certutil CRLDP URI code.
  • Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys.
  • Add ability to encrypt and decrypt CMS messages using ECDH.
  • Correct Templates for key agreement in smime/cmsasn.c.
  • Moving the decodedCert allocation to NSS.
  • Allow developers to speed up repeated local execution of NSS tests that depend on certificates.

Update to NSS 3.99:

  • Removing check for message len in ed25519 (bmo#1325335)
  • add ed25519 to SECU_ecName2params. (bmo#1884276)
  • add EdDSA wycheproof tests. (bmo#1325335)
  • nss/lib layer code for EDDSA. (bmo#1325335)
  • Adding EdDSA implementation. (bmo#1325335)
  • Exporting Certificate Compression types (bmo#1881027)
  • Updating ACVP docker to rust 1.74 (bmo#1880857)
  • Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 (bmo#1325335)
  • Add NSS_CMSRecipient_IsSupported. (bmo#1877730)

Update to NSS 3.98:

  • (CVE-2023-5388) Timing attack against RSA decryption in TLS
  • Certificate Compression: enabling the check that the compression was advertised
  • Move Windows workers to nss-1/b-win2022-alpha
  • Remove Email trust bit from OISTE WISeKey Global Root GC CA
  • Replace distutils.spawn.find_executable with shutil.which within mach in nss
  • Certificate Compression: Updating nss_bogo_shim to support Certificate compression
  • TLS Certificate Compression (RFC 8879) Implementation
  • Add valgrind annotations to freebl kyber operations for constant-time execution tests
  • Set nssckbi version number to 2.66
  • Add Telekom Security roots
  • Add D-Trust 2022 S/MIME roots
  • Remove expired Security Communication RootCA1 root
  • move keys to a slot that supports concatenation in PK11_ConcatSymKeys
  • remove unmaintained tls-interop tests
  • bogo: add support for the -ipv6 and -shim-id shim flags
  • bogo: add support for the -curves shim flag and update Kyber expectations
  • bogo: adjust expectation for a key usage bit test
  • mozpkix: add option to ignore invalid subject alternative names
  • Fix selfserv not stripping publicname: from -X value
  • take ownership of ecckilla shims
  • add valgrind annotations to freebl/ec.c
  • PR_INADDR_ANY needs PR_htonl before assignment to inet.ip
  • Update zlib to 1.3.1

Update to NSS 3.97:

  • make Xyber768d00 opt-in by policy
  • add libssl support for xyber768d00
  • add PK11_ConcatSymKeys
  • add Kyber and a PKCS#11 KEM interface to softoken
  • add a FreeBL API for Kyber
  • part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff
  • part 1: add a script for vendoring kyber from pq-crystals repo
  • Removing

Affected software

SUSE-RU-2024:2564-1 is recorded against 1 package.

  • mozilla-nss (fixed in 3.101.1-58.118.1)

Timeline and source

Published on 19 July 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-07-19
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
mozilla-nss 3.101.1-58.118.1

References

Free Vulnerability Check

Is your site affected by SUSE-RU-2024:2564-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-RU-2024:2564-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024