The following vulnerability was published for nss.
CVE-2023-5388[0]:
https://people.redhat.com/~hkario/marvin/ mentions that things
were improved in 3.6.1 via CVE-2023-4421, but CVE-2023-5388
was assigned for the remaining issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.