Ubuntu alert USN-8071-2 (nss)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8071-2] NSS vulnerability | |
| Date: | Thu, 05 Mar 2026 14:47:30 +0000 | |
| Message-ID: | <E1vy9z8-0004L4-SR@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8071-2 March 05, 2026 nss vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: NSS could be made to crash or run programs if it received specially crafted network traffic. Software Description: - nss: Network Security Service library Details: USN-8071-1 fixed a vulnerability in nss. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that NSS incorrectly handled memory when performing certain GHASH operations. A remote attacker could use this issue to cause NSS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libnss3 2:3.98-0ubuntu0.20.04.2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libnss3 2:3.35-2ubuntu2.16+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libnss3 2:3.28.4-0ubuntu0.16.04.14+esm5 Available with Ubuntu Pro Ubuntu 14.04 LTS libnss3 2:3.28.4-0ubuntu0.14.04.5+esm13 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8071-2 https://ubuntu.com/security/notices/USN-8071-1 CVE-2026-2781
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmmpl1sACgkQcpJm3tlz hgHB6Q//WS6LdslYT6LwZ6LqStLFHwKKoD0YzTk5rT4qfll1GRgfl1OclRO/6k77 dIczXB1XMO8FuDsC2YUCLQSfVYhQTGw2SWXb64cpOYmdE5J6uz2fj1G4Juq4qr32 +YrK7z0f46uZEq/UOdrUKYf7L6eZ1dk4r8146Kl9mufrzGtjz+ekYu4Zs0hz5J/y hH4QI01YEq63cwHA8qmLJ10aEik9/puZtSmeqOruqFBWiUo0n8JhIUl/y7Z8+8Ng uk8Hd/j2d0g2stu6O5aPAPYURp5tBhGqFBIYTQvjVwWDrnpeeYnP+g0GcVFOLhnh sjxfzN15dEBPuQMIOVFR7xl4Io7eOTEW9iMt62hb/LBJwygVWoYzCKsANkMhyGqv svAfIJjdeunhYwMw4VXv2XFBbrimORcSruJBQ1wpKUV5l9q0tTo5mhkEXM6coNOn U/CdCgOALfsJEx4i5GoTIdi8L3MGQJHgV2XdM7xC2quBoNGWNHl2nuC2XZbKw23z 1m/bf1CA8OuhEtZS+oQyUUzIpFgit5JUi4VAi40esLWtShQeUHyBby033KWzySkR rHo9mmC0HBCNT3DoWCRwh1j0b9tDapd0p/S04vG4wvpFTm13MgSCk14jONSHuN/j o492Bt0aEjmxfbCU3vuxiMKGEvPbgKwPJ9xxY/s3/rItdboceTw= =cHL5 -----END PGP SIGNATURE-----
