Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21713-1 advisory.
Changes in MozillaFirefox:
Firefox Extended Support Release 153.1.0 ESR.
* Fixed: Various security fixes.
MFSA 2026-77 (bsc#1274867):
* CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component
* CVE-2026-74935 Privilege escalation in the DOM: Networking component
* CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-74937 Use-after-free in the JavaScript: GC component
* CVE-2026-74938 Mitigation bypass in the JavaScript: GC component
* CVE-2026-74939 Privilege escalation in the DOM: Navigation component
* CVE-2026-74940 Use-after-free in the Graphics: Text component
* CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component
* CVE-2026-74942 Privilege escalation in the Remote Settings Client component
* CVE-2026-74943 Use-after-free in the Graphics: ImageLib component
* CVE-2026-74944 Use-after-free in the DOM: Core & HTML component
* CVE-2026-74945 Information disclosure in the Graphics: Text component
* CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
* CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component
* CVE-2026-74948 Information disclosure in the Graphics component
* CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics:
Canvas2D component
* CVE-2026-74950 Privilege escalation in the Downloads API component
* CVE-2026-74953 Privilege escalation in the Networking: Cookies component
* CVE-2026-74954 Information disclosure due to side-channel in the Storage:
Cache API component
* CVE-2026-74955 Privilege escalation in the Request Handling component
* CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component
* CVE-2026-74957 Mitigation bypass in the Safe Browsing component
* CVE-2026-74958 Information disclosure in the WebRTC component
* CVE-2026-74959 Mitigation bypass in the Storage: Cache API component
* CVE-2026-74960 Site isolation issue in the WebExtensions component
* CVE-2026-74961 Side-channel in the Web Audio component
* CVE-2026-74962 Site isolation issue in the Networking: Cookies component
* CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component
* CVE-2026-74964 Integer overflow in the Graphics component
* CVE-2026-74965 Privilege escalation in the Shell Integration component
* CVE-2026-74966 Information disclosure in the Form Autofill component
* CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component
* CVE-2026-74968 Site isolation issue in the Graphics: WebRender component
* CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component
* CVE-2026-74970 Site isolation issue in the Graphics component
* CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component
* CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component
* CVE-2026-74973 Race condition, use-after-free in the Graphics component
* CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component
* CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-74977 Integer overflow in the Graphics component
* CVE-2026-74978 Clickjacking issue in the Widget component
* CVE-2026-74979 Mitigation bypass in the Add-ons Manager component
* CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component
* CVE-2026-74982 Denial-of-service in the Widget component
* CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component
* CVE-2026-74984 Race condition in the JavaScript Engine component
* CVE-2026-74985 Privilege escalation in the Enterprise Policies component
* CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component
* CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
* CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
* CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Firefox Extended Support Release 153.0esr ESR
* New: ## General
- Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose.
Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data.
- Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs.
- The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type.
- Firefox now supports copying links directly to highlighted text on a webpage for easier sharing.
- Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences.
* New: ## AI
Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy.
* New: ## Sidebar and Tabs
- Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar.
- Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options.
- Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab.
- Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action.
- A Send Tab toolbar button is now available through Customize Toolbar.
* New: ## Security & Privacy
- Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes.
- Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission.
- Firefox now uses Safe Browsing V5 for phishing and malware protection.
- Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk.
- Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility.
* New: ## Translations
- Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality.
- A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox.
* New: ## Accessibility
- Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs.
* New: ## Linux
- Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays.
- Firefox no longer requires a restart after package manager updates and uses less memory on Linux.
- Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions.
* HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views.
- WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs.
- Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling.
* Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy.
- Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications.
- Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/.
* Fixed: Various security fixes.
- MFSA 2026-68 (bsc#1271649):
* CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component
* CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component
* CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component
* CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component
* CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component
* CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
* CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component
* CVE-2026-16365 Privilege escalation in the DOM: Workers component
* CVE-2026-16366 Privilege escalation in the DOM: Navigation component
* CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component
* CVE-2026-16354 Information disclosure in the Graphics: ImageLib component
* CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component
* CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component
* CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component
* CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component
* CVE-2026-16357 Incorrect boundary conditions in the Graphics component
* CVE-2026-16370 Mitigation bypass in the DOM: Networking component
* CVE-2026-16371 Privilege escalation in the DOM: Navigation component
* CVE-2026-16372 Privilege escalation in the DOM: Content Processes component
* CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android
* CVE-2026-16374 Information disclosure in the Framework component in DevTools
* CVE-2026-16375 Site isolation issue in the Networking: HTTP component
* CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component
* CVE-2026-16377 Mitigation bypass in the PDF Viewer component
* CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component
* CVE-2026-16379 Privilege escalation in the DOM: Content Processes component
* CVE-2026-16358 Site isolation issue in the Graphics: WebRender component
* CVE-2026-16380 Mitigation bypass in the Networking component
* CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component
* CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16383 Mitigation bypass in the DOM: Networking component
* CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16387 Site isolation issue in the Networking component
* CVE-2026-16388 Sandbox escape in the DOM: Networking component
* CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS
* CVE-2026-16390 Mitigation bypass in the Enterprise Policies component
* CVE-2026-16391 Information disclosure in the Storage: IndexedDB component
* CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component
* CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component
* CVE-2026-16394 Mitigation bypass in the DOM: Security component
* CVE-2026-16395 Integer overflow in the Audio/Video component
* CVE-2026-16396 Privilege escalation in WebExtensions
* CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android
* CVE-2026-16398 Site isolation issue in the Graphics component
* CVE-2026-16399 Site isolation issue in the DOM: Navigation component
* CVE-2026-16400 Information disclosure in the DOM: Security component
* CVE-2026-16401 Privilege escalation in the Data Loss Prevention component
* CVE-2026-16402 Integer overflow in the Graphics: ImageLib component
* CVE-2026-16403 Spoofing issue in the Address Bar component
* CVE-2026-16404 Spoofing issue in Firefox for Android
* CVE-2026-16405 Information disclosure in the Networking: WebSockets component
* CVE-2026-16406 Mitigation bypass in the Networking component
* CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16408 Integer overflow in the Audio/Video: Playback component
* CVE-2026-16409 Invalid pointer in the Security: PSM component
* CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16411 Memory safety bugs fixed in Firefox 153
* CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
* CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
Changes in mozilla-nss:
- Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698).
- Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263).
- Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772).
- Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773).
- Add zeroization for ML-KEM, ported from upstream (bsc#1272774).
- Add zeroization for ML-DSA (bsc#1272774).
- Add ML-DSA robustness and test fixes.
- Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262).
update to NSS 3.125
* Set nssckbi version to 2.88.
* Add Cybertrust Japan SecureSign Root CA16.
* Remove Email Trust bit from TrustAsia Global Root CA G3 and G4.
* Remove Entrust Root Certification Authority.
* Remove SecureSign Root CA12.
* Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket.
* replace references to nss-dev/nss with mozilla/nss.
* limit recursion depth in CMS decoder.
* clamp input.len to testString size in pk11_mergeSecretKey.
* NULL pointer dereference in CERT_MergeExtensions.
* CERT_DecodeAVAValue Integer Overflow in Output Buffer Sizing.
* fix two integer overflows on LLP64 systems.
* Modify an assertion in ssl3_ClientSendAppProtoXtn.
* Import RSA-PSS PKCS#8 private keys.
* Update fuzz/config/tstclnt_arguments.py.
* Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey.
* Adding a guard against integer overflow in AESKeyWrap_EncryptKWP.
* Add an integer overflow guard in UpdateBase64Decoder.
* Void out the fd.release in reconfig tests.
* make sftk_FindAttribute return a copy.
* Converted nss parameter schema from voluptuous to msgspec.
* drop slot monitor in PK11_ResetToken before calling PK11_InitToken.
* adjust the code to use nspr from github.
* avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword.
* test pk11auth.c functions with a non-threadsafe module.
* PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor.
* reject empty nickname in PK11_TraverseCertsForNicknameInSlot.
* validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen.
* guard space subtraction in ssl_CallCustomExtensionSenders.
* rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow.
* bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity.
* Set tail pointer to null in static slot lists when deallocating.
* avoid leaving a dangling ss->sec.ci.sid on allocation failure.
* guard against integer overflow in CERT_Hexify.
* Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1].
* NUL-terminate within filename field in jar_listtar to bound the filename scan.
* Widen CERT_FormatName length accumulator from unsigned to size_t.
* Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation.
* Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting.
* Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded.
* Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End.
* Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes.
* Guard padding read against empty output in SEC_PKCS7DecryptContents.
* Guard against keySize overflow in IKE PRF/PRF+ output sizing.
* Allocate values array when overwriting an empty CMS attribute.
* Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute.
* Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib.
* Handle zero-length input in PrepareBitStringForEncoding.
* Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest.
* Reject CKA_NSS_MODULE_SPEC values that arent NUL-terminated within ulValueLen.
* Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7.
* Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b.
* doc: import NSS:TryServer wiki page in the tree.
* improve PK11 URI tests.
* avoid nested attributeLock acquisition in sftk_CopyObject.
* doc: fix a typo in Community Network Security Services (NSS).
* acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair.
* Reject empty nickname in PK11_TraverseCertsForNicknameInSlot.
* require non-null session pointer in sftk_GetContext.
* set session->lastOpWasFIPS while holding session reference.
* atomically claim object removal in sftk_DeleteObject.
* atomically swap session search in NSC_FindObjects*.
* atomically install session contexts in C_*Init.
* hold session reference for context lifetime in C_*Update.
* align softoken session lock with head-bucket hash.
* restore reference counting for SFTKSession.
- update to NSS 3.124
* Add test for PKCS7 digest array alignment
* Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder
* Add test for CMS content size validation
* Add regression tests for DSAU signature decoding
* Add test for S/MIME profile lookup on temp certs
* Test case for post-handshake auth and many certificate requests
* Add test for intra-arena ASan redzones
* update nss_status flags one at a time
* add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR
* avoid PORT_Strdup in ssl_DecodeResumptionToken
* add runtime check on decoded resumption token session id
* improve mach try error handling
* clang format
* add comprehensive SECItem and SECItemArray tests
* add bugzilla_cf_status_nss.py script
* regenerate some recent release notes
* fix bug list output by release note and email scripts
* test removal from trust domain email cache
* fix testing if key corruption is detected in attribute failures with sqlite-3.53.0
* build sqlite3 shell for Windows CI runners
* avoid race with module unloading in NSSTrustDomain_FindTokensByURI
* add ImportEd25519WithNonEmptyAlgorithmParams test
* add CLAUDE.md and .mcp.json
* add a mach try command
* remove dead condition in sec_asn1d_check_and_subtract_length
* avoid integer truncation in nssCKObject_GetAttributes
* add defensive input validation to sftk_compute_ANSI_X9_63_kdf
* avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy]
* sdb: enforce that metaData's id key is unique when reading
* improve handling of escape sequences in pk11uri_ParseAttributes
* use correct data for ID comparison in transfer_uri_certs_to_collection
* fix truncation of ulValueLen in sdb_FindObjectsInit
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
* set previous-nss-release for abicheck
* Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData`
* consistently protect PK11SlotInfo::maxKeyCount with freeListLock
* Remove CRMF from testing and manifests
* Remove unused RSA blind signature implementation from freebl
- update to NSS 3.123.1
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
- update to NSS 3.123
* https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o
- update to NSS 3.122.2:
* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max
- update to NSS 3.122.1
* improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey.
* Improving the allocation of S/MIME DecryptSymKey.
* store email on subject cache_entry in NSS trust domain.
* Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation.
* Improve size calculations in CMS content buffering.
* avoid integer overflow while escaping RFC822 Names.
* Reject excessively large ASN.1 SEQUENCE OF in quickder.
* Deep copy profile data in CERT_FindSMimeProfile.
* Improve input validation in DSAU signature decoding.
* avoid integer overflow in RSA_EMSAEncodePSS.
* Add a maximum cert uncompressed len and tests.
* Clarify extension negotiation mechanism for TLS Handshakes.
* make ss->ssl3.hs.cookie an owned-copy of the cookie.
- update to NSS 3.122
* ensure permittedSubtrees don't match wildcards that could be outside the permitted tree.
* run mach doc-lint from generate_release_doc.py.
* Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag.
* tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable.
* fix cipher spec count intermittent CI failures.
* fix Mlkem768x25519ShareDamager intermittent CI failures.
* lint the legacy documentation.
* lint the NSS 3.112.3 release notes.
* add a doc-lint CI job.
* Add more useful coverage reports to CI and fail if new commit isn't tested.
* wrong alert for malformed TLS 1.3 Finished.
* Swap order of asserts and state check.
* set correct value of unused curve parameters in tls13_HandleKeyShare.
* GCM needs to check for various limits in FIPS mode.
* Get Key Length not working from ED and Montgomery keys.
* Not all ike modes are FIPS approved. Adjust the indicators when they aren't.
* fix intermittent ssl.sh test failures on windows runners.
* FIPS indicators on HKDF needs to be restricted to TLS usage.
* Generate keys not getting indicators.
* improve error handling in smime_init_once.
* Detect CPU features on OpenBSD using elf_aux_info.
* RSA_EMSAEncodePSS should validate the length of mHash.
* more robustly distinguish SFTKSessionObject and SFTKTokenObjects.
* fix missing .S file error in Solaris Makefile builds.
* fix memory leak in NSC_GenerateKey error path.
* Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions.
* release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths.
* release 1stHandshakeLock on SSL_ResetHandshake error path.
* avoid null deref in mp_div_d sign normalization.
* Temp private key lifecycle is broken.
* protect rwSessionCount with slotLock.
* Remove invalid PORT_Free().
* Fix intermittent ClientGreaseKeyShare test failure.
* Fix kCtxStr len passed to tls_SignOrVerifyUpdate.
* patch upstream acvp-rust during checkout to avoid build failures.
* update acvp Dockerfile.
* CKA_PARAM_SET missing from the CK_ULONG list in softoken.
* CKA_SEED missing from isPrivate in the database.
* update abicheck expectation for __nss_InitLock.
* taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds.
* tests: fix setup_policy to use ROOTCERTSFILE for root cert module path.
* tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT.
* tests: add native_path helper for cross-platform path conversion.
* tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows.
* avoid platform GCM for x64 iOS emulator builds.
* remove lock instrumentation feature.
* Move FIPS indicator structures out of fips_algorithms.h.
* all.sh is failing in FIPS SSL test in main tree.
* fix memory leaks in crmf tests.
* fix unsatisfiable condition in lg_getTrust.
* allow selfserv makefile build to use system zlib.
* Add allocation limit to pkcs12 decoding.
* Add text/html single-line example emails to NSS S/SMIME CMS tests.
- update to NSS 3.121
* update vendored zlib to v1.3.2.
* Revert the unnecessary changes to intel-gcm-wrap.gyp.
* Use C fallback for AES-GCM on MinGW builds.
* fix ML-KEM PCT.
* Extend NSS Fuzzing docs.
* avoid integer overflow in platform-independent ghash.
...
Please note that the description has been truncated due to length. Please refer to vendor advisory for the full description.
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: openSUSE-2026-21713-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:libfreebl3, p-cpe:/a:novell:opensuse:libsoftokn3, p-cpe:/a:novell:opensuse:mozilla-nspr-devel, p-cpe:/a:novell:opensuse:mozilla-nspr, p-cpe:/a:novell:opensuse:mozilla-nss-certs, p-cpe:/a:novell:opensuse:mozilla-nss-devel, p-cpe:/a:novell:opensuse:mozilla-nss-sysinit, p-cpe:/a:novell:opensuse:mozilla-nss-tools, p-cpe:/a:novell:opensuse:mozilla-nss, p-cpe:/a:novell:opensuse:mozillafirefox-branding-upstream, p-cpe:/a:novell:opensuse:mozillafirefox-devel, p-cpe:/a:novell:opensuse:mozillafirefox-translations-common, p-cpe:/a:novell:opensuse:mozillafirefox-translations-other, p-cpe:/a:novell:opensuse:mozillafirefox, p-cpe:/a:novell:opensuse:rust-cbindgen
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 8/31/2026
Vulnerability Publication Date: 7/21/2026
Reference Information
CVE: CVE-2026-16349, CVE-2026-16350, CVE-2026-16351, CVE-2026-16352, CVE-2026-16353, CVE-2026-16354, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16358, CVE-2026-16359, CVE-2026-16360, CVE-2026-16362, CVE-2026-16363, CVE-2026-16364, CVE-2026-16365, CVE-2026-16366, CVE-2026-16367, CVE-2026-16368, CVE-2026-16369, CVE-2026-16370, CVE-2026-16371, CVE-2026-16372, CVE-2026-16373, CVE-2026-16374, CVE-2026-16375, CVE-2026-16376, CVE-2026-16377, CVE-2026-16378, CVE-2026-16379, CVE-2026-16380, CVE-2026-16381, CVE-2026-16382, CVE-2026-16383, CVE-2026-16384, CVE-2026-16385, CVE-2026-16386, CVE-2026-16387, CVE-2026-16388, CVE-2026-16389, CVE-2026-16390, CVE-2026-16391, CVE-2026-16392, CVE-2026-16393, CVE-2026-16394, CVE-2026-16395, CVE-2026-16396, CVE-2026-16397, CVE-2026-16398, CVE-2026-16399, CVE-2026-16400, CVE-2026-16401, CVE-2026-16402, CVE-2026-16403, CVE-2026-16404, CVE-2026-16405, CVE-2026-16406, CVE-2026-16407, CVE-2026-16408, CVE-2026-16409, CVE-2026-16410, CVE-2026-16411, CVE-2026-16412, CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74937, CVE-2026-74938, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74947, CVE-2026-74948, CVE-2026-74949, CVE-2026-74950, CVE-2026-74953, CVE-2026-74954, CVE-2026-74955, CVE-2026-74956, CVE-2026-74957, CVE-2026-74958, CVE-2026-74959, CVE-2026-74960, CVE-2026-74961, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74966, CVE-2026-74967, CVE-2026-74968, CVE-2026-74969, CVE-2026-74970, CVE-2026-74971, CVE-2026-74972, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74977, CVE-2026-74978, CVE-2026-74979, CVE-2026-74981, CVE-2026-74982, CVE-2026-74983, CVE-2026-74984, CVE-2026-74985, CVE-2026-74986, CVE-2026-74987, CVE-2026-74988, CVE-2026-74990