[dev-tech-crypto] NSS 3.130 Release

4 views
Skip to first unread message

Anna Weine

unread,
8:01 AM (2 hours ago) 8:01 AM
to dev-tec...@mozilla.org
Network Security Services (NSS) 3.130 was released on 23 September 2026.

The HG tag is NSS_3_130_RTM. This version of NSS requires NSPR 4.39 or
newer. The latest version of NSPR is 4.39.

NSS 3.130 source distributions are available on ftp.mozilla.org for
secure HTTPS download:

<https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_130_RTM/src/>

Changes:
    Bug 2072042 - selfserv: drain connections before closing.
    Bug 2072396 - reduce core file detection frequency in CI runs.
    Bug 2074429 - applied clang-format on nss.
    Bug 2074515 - Include blapit.h to expose AES_BLOCK_SIZE and SHA_*_LENGTH.
    Bug 2073728 - remove some unused types and functions from lib/pki.
    Bug 2012680 - Testcases for DER_GetInteger error handling.
    Bug 2054712 - Don't accept post-handshake CertificateRequest in DTLS.
    Bug 1951159 -  release the decoded certificate when CERT_NewTempCertificate fails.
    Bug 2072384 - remove unnecessary certs dependencies in CI graph.
    Bug 2072554 - add missing return in do_key_slot when no internal key slot.
    Bug 2072682 - initialize referenceCount in crlutil's CRL allocations.
    Bug 2072682 - take a reference in cmsutil's CMS decrypt-key callback.
    Bug 2072682 - release-assert softoken session and db reference counts.
    Bug 2072682 - release-assert stan object reference counts.
    Bug 2072682 - release-assert pk11wrap slot, module and symkey reference counts.
    Bug 2072682 - release-assert SSL reference counts.
    Bug 2072682 - release-assert CRL and GeneralNameList reference counts.
    Bug 2072682 - free never-live symkeys directly in pk11_getKeyFromList.
    Bug 2072682 - abort on detected key object double frees.
    Bug 2072633 - return CKR_HOST_MEMORY when PORT_NewArena fails in jpakesftk.c.
    Bug 2072389 - fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey.
    Bug 2047359 - propagate the PKCS#12 max element length to nested decoders.
    Bug 2068001 - Switch NSS to WIN95 target and remove Windows fiber code.
    Bug 2030245 - Add Windows ARM64 build support to NSS.
    Bug 2019001 - Update policy for mlkem1024 named group and others.
    Bug 2061391 - perform session object removals under slot lock.
    Bug 2028690 - Keep the default input size limit in NSS_CMSMessage_CreateFromDER.
    Bug 2028690 - Thread element limits through the QuickDER decoder and raise them for CRLs.
    Bug 2028690 - Limit ASN.1 group element count and total streamed input.
    Bug 2028690 - Add SEC_QuickDERDecodeItemWithLimits.
    Bug 2028690 - Place a default size limit on ASN.1 decoder inputs.
    Bug 1951159 - populate NSSCertificate::id at creation.
    Bug 2064306 - avoid VLA in tls_ech_unittest.cc.
    Bug 2070118 - Change the error from decode_error to illegal_parameter for the case when update field in Key Update is neither update_requested nor update_not_requested.
    Bug 2064311 - Remove HPKE internals from public headers.
    Bug 2064306 - HPKE P-256 and P-384 KEMs.
    Bug 2070669 - NSS release process improvements.
    Bug 2070421 - Set _NSPR_BUILD_ for Windows builds.
    Bug 2064502 - add tsan build for NSS in treeherder.

NSS 3.130 shared libraries are backwards-compatible with all older NSS
3.x shared libraries. A program linked with older NSS 3.x shared
libraries will work with this new version of the shared libraries
without recompiling or relinking. Furthermore, applications that
restrict their use of NSS APIs to the functions listed in NSS Public
Functions will remain compatible with future versions of the NSS
shared libraries.

Bugs discovered should be reported by filing a bug report at
<https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS>

Release notes are available at

Anna
Reply all
Reply to author
Forward
0 new messages