ELA-1800-1 nss security update

arbitrary code execution

2026-08-11
Packagenss
Version2:3.26.2-1.1+deb9u11 (stretch), 2:3.42.1-1+deb10u12 (buster)
Related CVEs CVE-2026-16389


Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security Service library, which may result in execution of arbitrary code if a specially crafted certificate is processed.



For Debian 10 buster, these problems have been fixed in version 2:3.42.1-1+deb10u12.

For Debian 9 stretch, these problems have been fixed in version 2:3.26.2-1.1+deb9u11.

We recommend that you upgrade your nss packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.