| Package | nss |
|---|---|
| Version | 2:3.26.2-1.1+deb9u11 (stretch), 2:3.42.1-1+deb10u12 (buster) |
| Related CVEs | CVE-2026-16389 |
Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security Service library, which may result in execution of arbitrary code if a specially crafted certificate is processed.
For Debian 10 buster, these problems have been fixed in version 2:3.42.1-1+deb10u12.
For Debian 9 stretch, these problems have been fixed in version 2:3.26.2-1.1+deb9u11.
We recommend that you upgrade your nss packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.