Mozilla Network Security Service (NSS): TLS RSA decryption timing attack — GLSA 202508-04

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

Affected packages

dev-libs/nss on all architectures
Affected versions < 3.98
Unaffected versions >= 3.98

Background

The Mozilla Network Security Service is a library implementing security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME and X.509 certificates.

Description

A vulnerability has been discovered in Mozilla Network Security Service (NSS). Please review the CVE identifier referenced below for details.

Impact

Please review the referenced CVE identifier for details.

Workaround

There is no known workaround at this time.

Resolution

All Mozilla Network Security Service (NSS) users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-libs/nss-3.98"
 

References

Release date
August 06, 2025

Latest revision
August 06, 2025: 1

Severity
normal

Exploitable
local and remote

Bugzilla entries